{"id":11654,"date":"2026-03-25T12:46:37","date_gmt":"2026-03-25T12:46:37","guid":{"rendered":"https:\/\/events.aavar.org\/avar2025\/?page_id=11654"},"modified":"2026-03-25T12:48:39","modified_gmt":"2026-03-25T12:48:39","slug":"sniffing-around-unmasking-the-longnosedgoblin-operation-in-southeast-asia-and-japan","status":"publish","type":"page","link":"https:\/\/events.aavar.org\/avar2025\/index.php\/sniffing-around-unmasking-the-longnosedgoblin-operation-in-southeast-asia-and-japan\/","title":{"rendered":"Sniffing Around: Unmasking the LongNosedGoblin operation in Southeast Asia and Japan"},"content":{"rendered":"\n[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column]\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div style=\"height:200px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"banner-text has-x-large-font-size wp-block-paragraph\">AGENDA<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n<\/div>\n\n\n\n<p>[\/vc_column] [\/vc_row]<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"agenda-link wp-block-paragraph\"><strong><a href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/agenda\/\">&lt;&#8212; Back<\/a><\/strong><\/p>\n\n\n\n<p class=\"agenda-heading wp-block-paragraph\">Sniffing Around: Unmasking the LongNosedGoblin operation in Southeast Asia and Japan<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this talk, we will present a detailed case study of a cyberespionage campaign that we uncovered targeting organizations in Southeast Asia and Japan. We attribute this campaign to the LongNosedGoblin threat actor, which has been active since at least 2023.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our research reveals how LongNosedGoblin leverages Active Directory Group Policy to deliver custom malware across numerous workstations within compromised environments. One such payload, dubbed NosyHistorian, is a lightweight infostealer, designed to collect browser history, likely to help identify high-value targets within the affected organizations. Following this reconnaissance phase, the attackers deployed more advanced backdoors and data exfiltration tools. For instance, they used a full-featured backdoor we named NosyDoor, which leverages the Microsoft OneDrive service for command-and-control (C&amp;C) communications and includes functionality to bypass the Antimalware Scan Interface (AMSI).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During our presentation, we will deliver an in-depth analysis of the custom malware arsenal and the TTPs (tactics, techniques, and procedures) employed by this APT group. We will also detail our attribution process and explore potential links and overlaps with other threat actors operating in the region.<\/p>\n\n\n\n<div style=\"height:42px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Anton-Cherepanov.png\" alt=\"\" class=\"wp-image-11657\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Anton-Cherepanov.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Anton-Cherepanov-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Anton-Cherepanov-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Anton-Cherepanov-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong>Anton Cherepanov &#8211; ESET<\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anton Cherepanov is a Senior Malware Researcher at ESET, responsible for analyzing and hunting the most complex cyber threats. He has conducted extensive research on the Sandworm APT group. Anton has presented his findings at numerous international conferences, including Black Hat USA, Virus Bulletin, and CYBERWARCON. His professional interests include reverse engineering and hunting for previously unknown threats.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Peter-Strycek.png\" alt=\"\" class=\"wp-image-11658\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Peter-Strycek.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Peter-Strycek-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Peter-Strycek-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Peter-Strycek-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong>Peter Str\u00fd\u010dek &#8211; ESET<\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Peter Str\u00fd\u010dek is a Malware Researcher at ESET who enjoys reverse engineering and analyzing complex threats. He has a particular interest in analyzing malware targeting platforms such as Linux and macOS.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column] AGENDA [\/vc_column] [\/vc_row] &lt;&#8212; Back Sniffing Around: Unmasking the LongNosedGoblin operation in Southeast Asia and Japan In this talk, we will present a detailed case study of a cyberespionage campaign that we uncovered targeting organizations in Southeast Asia and Japan. We attribute this campaign to the LongNosedGoblin threat actor, which has been active since at<\/p>\n<div class=\"h10\"><\/div>\n<p><a class=\"more-link2\" href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/sniffing-around-unmasking-the-longnosedgoblin-operation-in-southeast-asia-and-japan\/\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-11654","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11654","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/comments?post=11654"}],"version-history":[{"count":2,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11654\/revisions"}],"predecessor-version":[{"id":11659,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11654\/revisions\/11659"}],"wp:attachment":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/media?parent=11654"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}