LongNosedGoblinLongNosedGoblin

Also known as: LongNosedGoblin

Known aliases
1

Profile

LongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs Group Policy for malware deployment and utilizes cloud services like Microsoft OneDrive and Google Drive as C&C servers. Their operations feature a modular malware ecosystem, including backdoors, browser data stealers, and PowerShell-based downloaders that execute multi-stage payloads in memory. LongNosedGoblin's tactics emphasize reconnaissance-driven targeting and the abuse of trusted enterprise mechanisms, allowing for stealthy persistence within compromised networks.

Aliases· 1

LongNosedGoblin

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
GOBLIN PANDA
Actor
GopherWhisper
Actor
APT37
Actor
DragonBreath
Actor
BlueHornet
Actor
APT27
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.