China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware
A sophisticated cyberespionage campaign targeting governmental entities in Southeast Asia and Japan has identified a new China-aligned threat actor, LongNosedGoblin.
A sophisticated cyberespionage campaign targeting governmental entities in Southeast Asia and Japan has identified a new China-aligned threat actor, LongNosedGoblin.
Active since at least September 2023, this advanced persistent threat (APT) group utilizes a diverse range of custom C#/.NET malware families.
The group's operations focus on intelligence gathering, employing stealthy techniques to infiltrate sensitive networks and maintain long-term access without detection.
A notable tactic involves abusing Windows Group Policy for lateral movement and malware deployment.
By compromising the Active Directory infrastructure, attackers distribute malicious payloads across networked machines, bypassing traditional perimeter defenses.
This method enables the propagation of tools like NosyHistorian, which harvests browser history to identify high-value targets for further exploitation of critical assets.
Active since at least September 2023, this advanced persistent threat (APT) group utilizes a diverse range of custom C#/.NET malware families.
The group's primary backdoor, NosyDoor, exemplifies their reliance on living-off-the-land techniques and cloud-based command and control infrastructure.
The malware operates through a complex three-stage execution chain designed to evade detection by standard security products.
The infection begins with a dropper component that decrypts embedded payloads using the Data Encryption Standard (DES) with the key UevAppMo.
This dropper employs execution guardrails to ensure the malware only detonates on specific victim machines.
Once validated, it establishes persistence by creating a scheduled task that executes a legitimate Windows binary, UevAppMonitor.exe, which the malware copies from System32 to the .NET framework directory.
The core of the evasion strategy lies in AppDomainManager injection, where attackers modify the configuration of the legitimate executable to load a malicious DLL.
This configuration file directs the application to initialize a custom domain from SharedReg.dll, bypassing the Antimalware Scan Interface (AMSI) and decrypting the final NosyDoor payload.
The backdoor retrieves its configuration and initiates communication with Microsoft OneDrive using RSA-encrypted metadata to receive commands stored in task files.
Based on reporting by Cyber Security News.
