Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors LongNosedGoblin

Also known as: APT34, Earth Preta, Stately Taurus, tracked as, Midnight Blizzard has, conference Wi-Fi portals worldwide, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, APT28, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, Evasive Panda

Description

LongNosedGoblin is a well‑coordinated threat actor that operates with the strategic objectives of gaining persistent access to high‑value targets in government and defense sectors across Southeast Asia and Japan. The group tailors its toolset around .NET frameworks, featuring custom loaders like NosyHistorian and shared malware families such as NosyDoor, which facilitate data collection, stealthy persistence, and lateral movement. In deployment, the actor exploits trusted enterprise mechanisms—most notably Group Policy—to sidestep perimeter defenses and spread laterally within compromised networks. It circumvents script‑scanning engines like AMSI and leverages living‑off‑the‑land capabilities including AppDomainManager injection to execute malicious payloads in memory. Command-and-control is largely conducted through legitimate cloud storage services (OneDrive, Yandex Disk) that provide a hardened tunneling environment. LongNosedGoblin’s operational footprint includes advanced exfiltration strategies: data collection spans browser histories, system configuration, and even video capture using FFmpeg, after which files are staged locally then transferred via public cloud or file‑sharing services. The actor demonstrates an aptitude for zero‑day exploitation—most recently the Cityworks CVE‑2025‑0994 vulnerability—to augment its compromise vectors. Overall, LongNosedGoblin exemplifies a sophisticated, multi‑stage adversary that blends native functionality with custom backdoors to achieve long‑term espionage objectives across targeted jurisdictions.

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications
Financial services
Non profit
Education
Think tank
Energy
Healthcare
Media
Maritime
Hospitality
Critical infrastructure
Manufacturing
Aerospace
Pharmaceutical
Transportation
Legal services
Nuclear
Entertainment
Aviation
Chemical
Utilities
Information technology

Targeted Countries / Regions

CN
RU
UA
US
JP
IL
AE
PK
BY
IN
IR
VN
PL
KR
KP
LB
TR
TW
KZ
IQ
DE
IT
SA
FR

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 1 day ago

Executive Summary

LongNosedGoblin is a China‑aligned advanced persistent threat group focused on cyberespionage against governmental, defense, and critical infrastructure entities in Southeast Asia and Japan. Leveraging living‑off‑the‑land techniques, the actor deploys .NET malware via Group Policy, uses cloud services such as OneDrive and Yandex Disk for command‑and‑control, and exfiltrates data through public file‑sharing platforms. The group’s operations are sophisticated, exploiting zero‑day vulnerabilities like Cityworks CVE‑2025‑0994 to establish further footholds.

Goals & Targeting

The organization’s primary aim is strategic intelligence collection against state actors and critical infrastructure operators in their target regions. By exploiting trusted systems, the group seeks persistent network access which enables ongoing monitoring, data harvesting (including operational documents, browser histories, and recorded conversations), and credential theft for broader lateral movement or future campaign phases. The focus on diplomatic officials and defense entities signals a deliberate effort to infiltrate decision‑making environments and obtain sensitive information that can influence geopolitical dynamics.

Enhanced Description

Key Capabilities

  • Collect browser history from Chrome, Edge, and Firefox
  • Gather machine metadata (hostname, username, OS, processes)
  • Execute shell commands on victim systems
  • Use OneDrive and Yandex Disk for command‑and‑control communication
  • Deploy malware via Group Policy to facilitate network lateral movement
  • Employ living‑off‑the‑land techniques including AppDomainManager injection
  • Bypass AMSI to evade script scanning
  • Shared Malware: NosyDoor
  • Audio‑video capture using FFmpeg
  • Backdoors targeting diplomatic officials
  • Custom loaders for lightweight malware deployment
  • Exfiltration via cloud and file-sharing services
  • .NET-based malware delivery (NetDraft/NosyDoor)
  • Zero‑day exploitation of Cityworks CVE-2025-0994

MITRE ATT&CK Tactics

Defense Evasion
Lateral Movement
Command and Control
Resource Development
Collection

ATT&CK Techniques

T1041
T1053.005
T1056.001
T1055
T1071
T1071.001
T1082
T1083
T1102.002
T1105
T1106
T1125
T1573.001
T1573.002
T1585.003
T1620
T1622
T1562.001
T1564.003
T1484.001
T1574.014

Software / Tooling

NosyHistorian
NosyDoor
Cobalt Strike
FFmpeg
NetDraft
SNOWLIGHT
VSHELL
Agent.btz
Gazer
Uroburos
ShadowPad
Net
Impacket
Tasklist
Systeminfo
pwdump
Donut
schtasks
phishing
Sednit
AdobeARM
ATI-Agent
MiniDionis
gpresult
wce
Turla
Tavdig
Wipbot
Agent.dne
WhiteBear
Neuron
Nautilus
PowerShell
Explorer
SNAPPYBEE
STOWAWAY

Campaigns & Victims

LongNosedGoblin conducts operations at an intermediate tempo, targeting governmental entities with high-value intelligence assets in Southeast Asia and Japan. Victim networks typically include defense ministries, telecommunications providers, and diplomatic missions where credentials and privileged information are abundant. The actor often deploys its .NET backdoors across multiple subnets using Group Policy or native tools, following up with lateral movement facilitated by AppDomainManager injection. Exfiltration tends to leverage public cloud services (OneDrive, Yandex Disk) rather than custom exfil channels, allowing detection only through traffic anomaly analysis. Notable attacks include the Cityworks CVE‑2025‑0994 zero‑day exploit used to bootstrap a VSHELL stager, and documented use of NosyDoor for espionage against Kurdish diplomatic officials.

IOC Patterns

  • ip-v4
  • file
  • domain

Recommended Actions

  • Monitor system processes for ffmpeg execution to detect covert audio‑video capture.
  • Block distribution and execution of NosyDoor and related shared malware families.
  • Deploy endpoint detection and response solutions capable of detecting .NET‑based malware such as NetDraft, NosyDoor, and SNOWLIGHT stagers.
  • Implement monitoring of outbound traffic to detect data exfiltration through cloud services like OneDrive, Yandex Disk, or other public file‑sharing platforms.
  • Apply timely patches for the Cityworks CVE-2025-0994 vulnerability to prevent zero‑day exploitation.
  • Enable and enforce AMSI protection to mitigate script‑based bypass attempts.
  • Restrict lateral movement via Group Policy changes and monitor for unauthorized policy modifications.

Suggested Tags

LongNosedGoblin
China-aligned
APT group
Cyberespionage
Government targeting
Southeast Asia
Japan
Group Policy lateral movement
AMSIBypass
Living-off-the-land
APT34
Iran-aligned
OilRig
Hazel Sandstorm
NetDraft
NosyDoor
VSHELL
Cityworks zero-day

Confidence Assessment

The assessment is based primarily on publicly released analyst reports and observed tool usage. While the core behaviors—Group Policy deployment, cloud‑based C2, .NET backdoors, and known asset exploitation—are well documented, attribution depth remains moderate due to limited internal indicator confirmation and potential overlap with related APT families (e.g., OilRig/APT34). Unknowns persist around the full geographic reach of the actor, exact operational tempo, and long‑term persistence mechanisms. Continuous monitoring and shared indicators are recommended to refine confidence over time.

ATT&CK Techniques

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. www.eset.com — Cited by web research for: APT34
  2. www.welivesecurity.com — Cited by web research for: T1585.003
  3. www.eset.com — Cited by web research for: NosyDownloader
  4. blog.talosintelligence.com — Cited by web research for: NetDraft
  5. www.welivesecurity.com — Cited by web research for: Information Technology

Intel Summary

37

Techniques

64

Tools

7

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

APT
Critical Infrastructure
Backdoor / C2
Government Targeting
Cyberespionage
China-aligned
Government targeting
Cloud C2
Southeast Asia
Japan
LongNosedGoblin
APT group
Group Policy lateral movement
AMSIBypass
Living-off-the-land
APT34
Iran-aligned
OilRig
Hazel Sandstorm
NetDraft
NosyDoor
VSHELL
Cityworks zero-day

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.