Chinese hacker group exploits Windows, releases malware
A group of Chinese hackers, taking advantage of Windows Group Policy, released malware on companies.
Windows Group Policy is another important tool for administrators, or Administrators, of enterprise IT to manage enterprise-level Windows policies, but this feature also has a vulnerability for hackers to use.
According to a report by the website Cyber Security News, the detection of spying campaigns against government agencies in Southeast Asia, including Thailand and Japan, by the work of Chinese-backed hackers like LongNosedGoblin, a research team from Welivesecurity, a subsidiary of the well-known anti-virus software developer ESET that has been monitoring the movements of such hackers for a long time, has revealed that hackers have been moving since 2023 (2024) using malware created on C # and C #. NET to invade the target's system with the aim of obtaining information from the victim's system.
One interesting attack technique is that the group has used a feature to oversee the system policies of employees in an organization like Windows Group Policy to spread malware to other points of the system within the organization, or Lateral Movement, and also to release other malware into the system through this channel. It relies on the infrastructure of an Active Directory folder management system to spread malware into machines within the organization and avoid malware detection systems at the same time.
Using this tool to spread malware, the research team found that it was used to spread NosyHistorian malware into targeted organizations with the aim of stealing data on web browsers, where the malware was first detected in the year 2024. (2567) According to an investigation of a network attack on a Southeast Asian state organization, several machines within the same network were infected with this malware. Evidence of the use of Windows Group Policy comes from the detection of policy files such as History.ini and Registry .pol that hackers forged as real files to modify the settings in the use of the feature.
In addition to the above-mentioned malware, it has been found to be used to spread malware of the type that creates a login back door or a backdoor called NosyDoor with the beginning of sending malware down the system. It starts by converting the Registry .pol file first to act as a malware extension (Dropper), leading to the decryption of malware files (Payload) by using the Data Encryption Standard (DES) with a key called UevAppMo. In addition to that, to prevent malware from being grunned on non-target machines, the Dropper also inadvertently ran anti-malware or Guardrails to Prevented, too.
After confirming that the Payload file has been properly released on the target machine, the malware will create a persistence in the system by creating a task schedule that will run the UevAppMonitor.exe file, a valid Windows application file that has been copied from the System32 folder to the. NET framework to implement the task as a malware tool with application implementation techniques already on the machine; or Living-off-the-Land through firing (Injection), a new setup of AppDomainManager to lead to the loading of NosyDoor malware DLL files.
In the next step, after the malware has successfully received the Configuration value, the malware decrypts the received settings (under the name log.cached, beautified) and then uses that setting to contact Microsoft OneDrive through the RSA-encrypted Metadata to retrieve commands (Command) within OneDrive in the Task File section to work on the next step.
# Welcome 2026 # Take care of yourself # Open budget # Includes IT matters # Trending
จากประสบการณ์การติดตามข่าวสารและวิธีป้องกันด้านความปลอดภัยในองค์กร พบว่าเครื่องมืออย่าง Windows Group Policy ถือเป็นหนึ่งในฟีเจอร์ที่องค์กรต่างๆ ใช้กันอย่างแพร่หลายเพื่อบริหารจัดการการตั้งค่าระบบให้เป็นไปตามนโยบายขององค์กรแต่ก็มีความเสี่ยงสูงเมื่อแฮกเกอร์สามารถเข้าควบคุมและใช้เป็นช่องทางปล่อยมัลแวร์ได้ การที่แฮกเกอร์กลุ่ม LongNosedGoblin ใช้เทคนิคแบบ Living-off-the-Land ทำให้มัลแวร์สามารถซ่อนตัวได้ดีและยากต่อการตรวจจับ เนื่องจากใช้เครื่องมือและไฟล์ระบบที่มีอยู่แล้วใน Windows เช่น UevAppMonitor.exe ที่ทำให้มัลแวร์สามารถสร้างความคงอยู่ในระบบและทำงานได้อย่างต่อเนื่องโดยไม่ถูกสงสัย วิธีการแพร่กระจายมัลแวร์ผ่านไฟล์ Registry.pol ที่ถูกดัดแปลงเพื่อใช้ปล่อยมัลแวร์ NosyDoor นั้น ถือว่าหลักแหล่งและมีการเข้ารหัสข้อมูลอย่างแนบเนียนโดยใช้มาตรฐานอย่าง RSA และ DES ทำให้การสืบสวนและลบมัลแวร์เหล่านี้มีความซับซ้อนมากขึ้น การใช้งาน Microsoft OneDrive ในการรับคำสั่งและควบคุมมัลแวร์ก็เป็นอีกหนึ่งกลยุทธ์ที่ช่วยให้มัลแวร์สามารถทำงานเชื่อมต่อกับโครงข่ายระยะไกลได้อย่างราบรื่นและปลอดภัยจากการตรวจจับที่เคร่งครัดของระบบป้องกัน สำหรับองค์กรที่ต้องการป้องกันตัวเอง ควรมีการตรวจสอบนโยบาย Group Policy อย่างเข้มงวด นำระบบตรวจจับพฤติกรรมผิดปกติ (Behavioral Detection) เข้ามาช่วยเสริม พร้อมทั้งติดตั้งซอฟต์แวร์แอนตี้ไวรัสและอัปเดตระบบ Windows อยู่เสมอ นอกจากนี้การฝึกอบรมพนักงานเรื่องความปลอดภัยไซเบอร์ และการจัดระเบียบสิทธิ์การเข้าถึงระบบอย่างเหมาะสมจะช่วยลดความเสี่ยงที่จะถูกโจมตีจากช่องโหว่เหล่านี้ได้อย่างมาก การติดตามและวิเคราะห์พฤติกรรมของมัลแวร์ที่แฝงตัวด้วยวิธี Living-off-the-Land ยังเป็นสิ่งจำเป็นสำหรับผู้ดูแลระบบ IT หากพบเจอไฟล์หรือกิจกรรมที่น่าสงสัยควรมีการแจ้งเตือนและตอบสนองอย่างรวดเร็ว เพื่อป้องกันการลุกลามและเพิ่มความเสียหายต่อองค์กรในระยะยาว
