Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware

A sophisticated cyberespionage campaign targeting governmental entities in Southeast Asia and Japan has identified a new China-aligned threat actor, LongNosedGoblin.

A sophisticated cyberespionage campaign targeting governmental entities in Southeast Asia and Japan has identified a new China-aligned threat actor, LongNosedGoblin.

Active since at least September 2023, this advanced persistent threat (APT) group utilizes a diverse range of custom C#/.NET malware families.

The group's operations focus on intelligence gathering, employing stealthy techniques to infiltrate sensitive networks and maintain long-term access without detection.

A notable tactic involves abusing Windows Group Policy for lateral movement and malware deployment.

By compromising the Active Directory infrastructure, attackers distribute malicious payloads across networked machines, bypassing traditional perimeter defenses.

This method enables the propagation of tools like NosyHistorian, which harvests browser history to identify high-value targets for further exploitation of critical assets.

Active since at least September 2023, this advanced persistent threat (APT) group utilizes a diverse range of custom C#/.NET malware families.
Lucas Gallagher · Thehackingpost

The group's primary backdoor, NosyDoor, exemplifies their reliance on living-off-the-land techniques and cloud-based command and control infrastructure.

The malware operates through a complex three-stage execution chain designed to evade detection by standard security products.

The infection begins with a dropper component that decrypts embedded payloads using the Data Encryption Standard (DES) with the key UevAppMo.

This dropper employs execution guardrails to ensure the malware only detonates on specific victim machines.

Advertisement

Once validated, it establishes persistence by creating a scheduled task that executes a legitimate Windows binary, UevAppMonitor.exe, which the malware copies from System32 to the .NET framework directory.

The core of the evasion strategy lies in AppDomainManager injection, where attackers modify the configuration of the legitimate executable to load a malicious DLL.

This configuration file directs the application to initialize a custom domain from SharedReg.dll, bypassing the Antimalware Scan Interface (AMSI) and decrypting the final NosyDoor payload.

The backdoor retrieves its configuration and initiates communication with Microsoft OneDrive using RSA-encrypted metadata to receive commands stored in task files.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories