Automatically translated.View original post

Chinese hacker group exploits Windows, releases malware

A group of Chinese hackers, taking advantage of Windows Group Policy, released malware on companies.

Windows Group Policy is another important tool for administrators, or Administrators, of enterprise IT to manage enterprise-level Windows policies, but this feature also has a vulnerability for hackers to use.

According to a report by the website Cyber Security News, the detection of spying campaigns against government agencies in Southeast Asia, including Thailand and Japan, by the work of Chinese-backed hackers like LongNosedGoblin, a research team from Welivesecurity, a subsidiary of the well-known anti-virus software developer ESET that has been monitoring the movements of such hackers for a long time, has revealed that hackers have been moving since 2023 (2024) using malware created on C # and C #. NET to invade the target's system with the aim of obtaining information from the victim's system.

One interesting attack technique is that the group has used a feature to oversee the system policies of employees in an organization like Windows Group Policy to spread malware to other points of the system within the organization, or Lateral Movement, and also to release other malware into the system through this channel. It relies on the infrastructure of an Active Directory folder management system to spread malware into machines within the organization and avoid malware detection systems at the same time.

Using this tool to spread malware, the research team found that it was used to spread NosyHistorian malware into targeted organizations with the aim of stealing data on web browsers, where the malware was first detected in the year 2024. (2567) According to an investigation of a network attack on a Southeast Asian state organization, several machines within the same network were infected with this malware. Evidence of the use of Windows Group Policy comes from the detection of policy files such as History.ini and Registry .pol that hackers forged as real files to modify the settings in the use of the feature.

In addition to the above-mentioned malware, it has been found to be used to spread malware of the type that creates a login back door or a backdoor called NosyDoor with the beginning of sending malware down the system. It starts by converting the Registry .pol file first to act as a malware extension (Dropper), leading to the decryption of malware files (Payload) by using the Data Encryption Standard (DES) with a key called UevAppMo. In addition to that, to prevent malware from being grunned on non-target machines, the Dropper also inadvertently ran anti-malware or Guardrails to Prevented, too.

After confirming that the Payload file has been properly released on the target machine, the malware will create a persistence in the system by creating a task schedule that will run the UevAppMonitor.exe file, a valid Windows application file that has been copied from the System32 folder to the. NET framework to implement the task as a malware tool with application implementation techniques already on the machine; or Living-off-the-Land through firing (Injection), a new setup of AppDomainManager to lead to the loading of NosyDoor malware DLL files.

In the next step, after the malware has successfully received the Configuration value, the malware decrypts the received settings (under the name log.cached, beautified) and then uses that setting to contact Microsoft OneDrive through the RSA-encrypted Metadata to retrieve commands (Command) within OneDrive in the Task File section to work on the next step.

# Welcome 2026 # Take care of yourself # Open budget # Includes IT matters # Trending

1/7 Edited to

... Read moreจากประสบการณ์การติดตามข่าวสารและวิธีป้องกันด้านความปลอดภัยในองค์กร พบว่าเครื่องมืออย่าง Windows Group Policy ถือเป็นหนึ่งในฟีเจอร์ที่องค์กรต่างๆ ใช้กันอย่างแพร่หลายเพื่อบริหารจัดการการตั้งค่าระบบให้เป็นไปตามนโยบายขององค์กรแต่ก็มีความเสี่ยงสูงเมื่อแฮกเกอร์สามารถเข้าควบคุมและใช้เป็นช่องทางปล่อยมัลแวร์ได้ การที่แฮกเกอร์กลุ่ม LongNosedGoblin ใช้เทคนิคแบบ Living-off-the-Land ทำให้มัลแวร์สามารถซ่อนตัวได้ดีและยากต่อการตรวจจับ เนื่องจากใช้เครื่องมือและไฟล์ระบบที่มีอยู่แล้วใน Windows เช่น UevAppMonitor.exe ที่ทำให้มัลแวร์สามารถสร้างความคงอยู่ในระบบและทำงานได้อย่างต่อเนื่องโดยไม่ถูกสงสัย วิธีการแพร่กระจายมัลแวร์ผ่านไฟล์ Registry.pol ที่ถูกดัดแปลงเพื่อใช้ปล่อยมัลแวร์ NosyDoor นั้น ถือว่าหลักแหล่งและมีการเข้ารหัสข้อมูลอย่างแนบเนียนโดยใช้มาตรฐานอย่าง RSA และ DES ทำให้การสืบสวนและลบมัลแวร์เหล่านี้มีความซับซ้อนมากขึ้น การใช้งาน Microsoft OneDrive ในการรับคำสั่งและควบคุมมัลแวร์ก็เป็นอีกหนึ่งกลยุทธ์ที่ช่วยให้มัลแวร์สามารถทำงานเชื่อมต่อกับโครงข่ายระยะไกลได้อย่างราบรื่นและปลอดภัยจากการตรวจจับที่เคร่งครัดของระบบป้องกัน สำหรับองค์กรที่ต้องการป้องกันตัวเอง ควรมีการตรวจสอบนโยบาย Group Policy อย่างเข้มงวด นำระบบตรวจจับพฤติกรรมผิดปกติ (Behavioral Detection) เข้ามาช่วยเสริม พร้อมทั้งติดตั้งซอฟต์แวร์แอนตี้ไวรัสและอัปเดตระบบ Windows อยู่เสมอ นอกจากนี้การฝึกอบรมพนักงานเรื่องความปลอดภัยไซเบอร์ และการจัดระเบียบสิทธิ์การเข้าถึงระบบอย่างเหมาะสมจะช่วยลดความเสี่ยงที่จะถูกโจมตีจากช่องโหว่เหล่านี้ได้อย่างมาก การติดตามและวิเคราะห์พฤติกรรมของมัลแวร์ที่แฝงตัวด้วยวิธี Living-off-the-Land ยังเป็นสิ่งจำเป็นสำหรับผู้ดูแลระบบ IT หากพบเจอไฟล์หรือกิจกรรมที่น่าสงสัยควรมีการแจ้งเตือนและตอบสนองอย่างรวดเร็ว เพื่อป้องกันการลุกลามและเพิ่มความเสียหายต่อองค์กรในระยะยาว

Related posts

How to become insanely over educated in 2026
#nursingstudent #medschool #nursingschool #medstudent #studymotivation
Nursing exploits

Nursing exploits

12.1K likes

Tools and sites I use as a cybersecurity student 🌸
#cybersecuritystudent #cybersecurity #techgirlie
LexiStudies

LexiStudies

102 likes

Fun Roblox Games to Kill Your Boredom✨
Looking for exciting and entertaining Roblox games to dive into? These games offer unique challenges and plenty of fun for solo players or groups. Check them out: 1.Taxi Boss✨ Test your driving skills and hustle your way to the top in this fast-paced game. Pick up passengers, customize your car
Nathally

Nathally

16.8K likes

Study tips for overthinkers
#studytips #StudyHacks #universitylife #studylife #examstudytips
Nursing exploits

Nursing exploits

800 likes

Study anatomy with me
#studyanatomy #medschoollife #nursingstudenttips #medstudent #studywithme
Nursing exploits

Nursing exploits

413 likes

How to study in 2026🧠📚
#nursingstudent #nursingexam #medschool #StudyHacks #studygram
Nursing exploits

Nursing exploits

867 likes

Narcissism 5 types…
#narcissist #journaling I’m not going to lie…I read these definitions and thought to myself….am I a narcissist? I’m not sure but I think Narcissism is when you are incapable of loving others. I know it’s okay to love yourself…but…damn I’m still confused. I feel like people don’t truly love
PlanetTiffness 🤙

PlanetTiffness 🤙

324 likes

How to stay awake during exams by a med student
Powered by caffeine without the crash/jitters #studytips #medschool #nursingstudent #medstudent #nursingschool
Nursing exploits

Nursing exploits

31 likes

How to overeducate yourself as a lazy girl
#lazytips #lazygirlstudying #StudyHacks #medschool #nursingschool
Nursing exploits

Nursing exploits

4678 likes

Less scrolling, more living
Here’s what I did #nursingstudent #medschool #nursingschool #studymotivation #medstudent
Nursing exploits

Nursing exploits

15 likes

Welcome to the practical magic side of TikTok ✨🌧️ Where the candles burn slow, the rain whispers spells, and the vibes are darkly cozy. #PracticalMagic #WitchyVibes #MoodyAesthetic #DarkCottagecore #Whimsigoth #CozyWitchTok #RainyDayVibes #CottagecoreMagic #Witchcore #OutdoorAmbience
hannahreneex23

hannahreneex23

201 likes

5 high yield questions you could be asked
#medschool #nursingstudent #medstudent #nursingschool #studytips
Nursing exploits

Nursing exploits

9 likes

Memorization made easy
#memorization #medschool #nursingschool #examseason #finalsweek
Nursing exploits

Nursing exploits

23 likes

“Don’t become a doctor if you wanna get married”
Some myths and concepts broken #youngmarried #nursingstudent #medschool #nursingschool #medstudent
Nursing exploits

Nursing exploits

15 likes

More Meghan Markle controversy 👀 The Girl Scouts and critics are fuming! Some claim she didn’t even watch the documentary before signing on as executive producer—and here’s why. Thoughts? #MeghanMarkle #PrinceHarry #AsEver #SussexRoyal #WithLoveMeghan
Cactus Crumpet

Cactus Crumpet

0 likes

Reasons To Buy Handmade 💛
there are so many reasons to buy handmade items! let me know what your reason is in the comments below ⬇️ #buyhandmade #shopsmall #colorfulfashion #colorfulaesthetic #crochetsunflower #crochetstrawberry #handmadevibes #cutecrochetingideas #shophandmade #Lemon8Diary
Noella 🐞

Noella 🐞

23 likes

Happy Augtober to everyone romanticizing the slow shift from summer sunshine to spooky season vibes 🎃✨ You’ll catch me sipping cozy drinks, lighting candles, and fully pretending it’s October already 🕯️🌻🍂📖 #softspookyseason #Augtober #CozyVibes #Summerween #SpookySeasonPrep #Cottageco
hannahreneex23

hannahreneex23

18 likes

sad girl cinema
sad girls in movies doing it for all of us 👇🏻 🖤Ghost World - unlikeable female protagonists are fun 🖤Gia - no one does sad like angelina. i love crying 🖤Atonement - truly one of the saddest movies i’ve ever watched 🖤Blue Valentine - this one could honestly be a horror movie with the way i
sav

sav

1138 likes

4 【Idiom Story】The fox exploits the tiger‘s might
The story of "The Fox Borrows the Tiger's Might" conveys the lesson that some people rely on the power of others to achieve their goals. Although they may appear strong on the surface, they lack real strength. This idiom warns us not to be deceived by appearances and reminds us that exc
Alex‘s idiom

Alex‘s idiom

9 likes

Study Tips by an award-winning med student
#studytipsforstudents #medschool #nursingstudent #nursingschool #relatablelifestyle
Nursing exploits

Nursing exploits

6 likes

someone asked
do y’all like these kinds of content idk what to do
Liv

Liv

93 likes

2 Cheap Nintendo games. ✨
If you like animal crossing I think you’ll love stardew valley. It’s also multiplayer. If you already play stardew I can post about a few cheats and exploits to help you with your game. What other games do you guys play ? I have a few more I can share. #nintendo switch #gamergirl
Shawna S.

Shawna S.

227 likes

Sex club book Recommendations 🥵🙃🔥
Available on Amazon! :) #darkromancebooks #darkromancereader #spicyrecommendations #bookrecommendations
littleb_TX

littleb_TX

45 likes

that will kill our boredom
ꨄ

298 likes

TV SHOWS TO WATCH
•Little Fires Everywhere - Hulu A single mother and her daughter move to a suburb in Ohio and become involved with a picture perfect rich family. Mia is an artist with secrets about her past, while Elena is a stickler for rules and status quo. The plot unfolds when both families are on opposing sid
A A L I Y A H

A A L I Y A H

1454 likes

AI Explorer

AI Explorer

0 likes

No one ever taught you how to heal yourself.
It’s all up to you to always be in top condition, no matter the cost or toll it takes on you #healinghustle #nursingschool #nursing #healingmindset #medschool
Nursing exploits

Nursing exploits

11 likes

Quantum Mechanics 101
#physicstok #quantummechanics #richardfeynman #quantumphysics #wernerheisenberg
sarah abou hadir

sarah abou hadir

5 likes

Replying to @Kenshins Closet 2 Weeks away! Jade Leech fun facts 🐬 #jadeleech #twst #twistedwonderland #ツイステ #ツイステッドワンダーランド
MandaNeverLeft

MandaNeverLeft

3 likes

KimberlyB68

KimberlyB68

0 likes

Replying to @Dumb_Dolly Its all connected. It’s all one big project. #iran #sudan #trumpwar #uae #congo
Kiki Rae Real

Kiki Rae Real

8 likes

Feeling betrayed @Netflix 😭 also why is Google playing the game too #strangerthings #conformitygate #episode9 #betrayed
Cassie.meschke

Cassie.meschke

22 likes

Tabi_isHER24

Tabi_isHER24

0 likes

bored af this game
AnonGaming

AnonGaming

0 likes

Handlers
Eddie Morris

Eddie Morris

0 likes

Replying to @Poop farter #doawk #diaryofawimpykid #bookrecs #parody #femcel
snaptocks

snaptocks

2 likes

Jesus Flipping Tables: Authority vs Permission
God’s House Church

God’s House Church

2 likes

If you ever wanna know where America is going to go next, look where Israel already is. Or Taiwan. Or one of our many other proxy states. And those tea leaves are very clearly pointing to south and Central America, a return of the Monroe doctrine
Will McC

Will McC

0 likes

A "thug kind of love" isn't a fairy tale. It's a trap. It takes the kindness, the dreams, and the light from a good girl and replaces it with fear and silence. But silence doesn't have to be the end of the story. You deserve a love that builds you up, not tears you down. A love
Mrs. Fisher Blunt

Mrs. Fisher Blunt

2 likes

what not to say during your thesis😅💯
#nursingschool #nursingexam #tipsforstudents #successhabits #thesis
Nursing exploits

Nursing exploits

5 likes

Upcoming book releases for the hopeless romantic 💖
As a HUGE Ali Hazelwood fan, I’m incredibly excited for her two upcoming releases this year! First up we have Problematic Summer Romance which I already KNOW I’m going to love. Her books always combine smart, witty characters with heartfelt emotion and irresistible chemistry. I love how she cre
Bethany Taylor

Bethany Taylor

78 likes

Theinfluentialqueen_

Theinfluentialqueen_

0 likes

OHEMAH EXPLOITS

OHEMAH EXPLOITS

1 like

This is so sad! 😭
The new documentary, “Where is Wendy Williams?” was aired on Lifetime a few days ago and it was so sad! It had drawn a lot of attention because so many people were speculating what happened to her & now we know. 😞 what’s really happening with Wendy// 💭: she went absent from her show & t
Marianne Nafsu

Marianne Nafsu

56 likes

9 psychology facts
many of the points I shared are rooted in psychological concepts and behaviors, often studied within the fields of social psychology, forensic psychology, and behavioral psychology. However, some points are more about specific tactics or behaviors associated with dark psychology rather than pure sc
Itsaseirra

Itsaseirra

205 likes

See more