A number of cyberattacks against governmental organizations in Southeast Asia and Japan have been linked to LongNosedGoblin, an undiscovered China-aligned threat cluster.
According to a report released today by Slovak cybersecurity firm ESET, the ultimate objective of these operations is cyber espionage. It has been determined that the threat activity cluster has been active since at least September 2023.
According to security experts Anton Cherepanov and Peter Strěček, LongNosedGoblin leverages cloud services like Google Drive and Microsoft OneDrive as command and control (C&C) servers and Group Policy to spread malware throughout the affected network.
On Windows computers, Group Policy is a tool for controlling permissions and settings. Microsoft claims that Group Policy can be used to administer server systems read more about China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
