Skip to content
LongNosedGoblin and UAT-8302: New China-Aligned APT Threats Targeting Governments

LongNosedGoblin and UAT-8302: New China-Aligned APT Threats Targeting Governments

First seen 5 May 2026, 10:34 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 6, 2026 at 09:27 UTC

In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to conduct cyberespionage. Key tools include NosyDoor, a backdoor utilizing Microsoft OneDrive for command and control, and NosyHistorian, which collects browser history to inform further attacks. Concurrently, Talos reported on UAT-8302, another China-nexus APT group, which uses similar tactics and tools, including the malware NetDraft, also known as NosyDoor. Both groups are linked through their use of advanced malware and tactics for credential extraction and network proliferation. The campaigns indicate a coordinated effort to maintain long-term access to sensitive government systems. The ongoing threat remains significant, with multiple victims affected across different regions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 130d ago How this analysis works

Timeline

2024-01-01
Talos attributes UAT-8302 to China-nexus APT activities.
2024-01-01
UAT-8302 deploys malware including NetDraft against various targets.
2024-02-01
ESET discovers malware on a Southeast Asian governmental entity.
2024-02-01
NosyDoor backdoor identified in the same campaign.
2026-05-05
Both articles published detailing the APT groups and their activities.

More articles in this cluster (8)

Following this threat?

Track Apt27, CloudSorcerer and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed