Threat Management, Threat Hunting, Threat Intelligence, Governance, Risk and Compliance

Windows Group Policy exploited in novel Chinese cyberespionage campaign

Chinese hacker. Laptop with binary computer code and china flag

Newly discovered China-linked threat operation LongNosedGoblin has leveraged Windows Group Policy to compromise Southeast Asian and Japanese government organizations with malware as part of a cyberespionage campaign, according to The Hacker News.

Abusing Windows Group Policy has allowed LongNosedGoblin to modify configuration definitions and deploy the NosyHistorian tool to obtain browser history, the NosyDoor backdoor to enable file exfiltration and shell command execution, and the NosyStealer browser data stealer, as well as the NosyDownloader and NosyLogger tools, a report from ESET showed. Attacks have also involved a reverse SOCKS5 proxy, a video recorder-executing utility, and a Cobalt Strike loader, said researchers, who noted similarities between LongNosedGoblin and the ToddyCat and Erudite Mogwai threat clusters.

"We later identified another instance of a NosyDoor variant targeting an organization in an EU country, once again employing different TTPs, and using the Yandex Disk cloud service as a C&C server. The use of this NosyDoor variant suggests that the malware may be shared among multiple China-aligned threat groups," researchers added.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds