# LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

DevFeed: [LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan](<https://devfeed.tech/articles/longnosedgoblin-tries-to-sniff-out-governmental-affairs-in-southeast-asia-and-japan-8374.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/>)

Author: Anton Cherepanov Peter Strýček

Published: 2025-12-18T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [.NET](<https://devfeed.tech/topics/net.md>), [enterprise deployment](<https://devfeed.tech/topics/enterprise-deployment.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [browser](<https://devfeed.tech/tags/browser.md>), [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [china](<https://devfeed.tech/tags/china.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-services](<https://devfeed.tech/tags/cloud-services.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [google](<https://devfeed.tech/tags/google.md>), [japan](<https://devfeed.tech/tags/japan.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [net](<https://devfeed.tech/tags/net.md>), [policy](<https://devfeed.tech/tags/policy.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [windows](<https://devfeed.tech/tags/windows.md>)

## AI overview

ESET describes LongNosedGoblin, a China-aligned APT group conducting cyberespionage against governmental entities in Southeast Asia and Japan. The group deploys malware through Group Policy and uses tools including the NosyDoor backdoor and the C#/.NET NosyHistorian application.

## Source excerpt

ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions