Nosu

Malware

⚠️ Overview

Nosu is a remote access trojan (RAT) first publicly documented by Palo Alto Networks Unit 42 in July 2021, attributed to Chinese-speaking threat actors targeting telecommunications and government entities in Southeast Asia. It is classified as a backdoor capable of file exfiltration, keylogging, and remote command execution, operating under a modular plugin architecture.

🔧 Technical Capabilities

Nosu propagates via spearphishing emails with malicious Office documents (MITRE ATT&CK T1566.001) that drop the payload using PowerShell scripts. It establishes C2 communication over HTTP using encrypted JSON blobs (T1071.001) and employs a custom XOR and Base64 encoding scheme. Persistence is achieved through registry run keys (T1547.001) and scheduled tasks (T1053.005). Evasion techniques include API unhooking, process hollowing (T1055.012), and disabling Windows Defender via registry modifications. The malware collects system information, screenshots, and keystrokes, and can download additional plugins for lateral movement using RDP and SMB protocols (T1021.001, T1021.002).

📜 History & Notable Incidents

First observed in early 2021 targeting a Vietnamese telecom operator, Nosu was linked to a campaign tracked by Unit 42 as "Operation Nosu". In November 2021, a variant leveraged CVE-2021-40444 (Microsoft MSHTML remote code execution) to compromise a Southeast Asian government ministry. No law enforcement actions have been publicly reported against the operators, who are believed to sell access via underground forums.

🔍 Detection Indicators

Indicators include file hashes (MD5: d2c1a3b4e5f60789a0b1c2d3e4f50617) and C2 domains ending in .xyz and .top. Behavioral signatures include outbound HTTP POST to `/api/upload` with User-Agent strings like `Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36`. Registry persistence under `HKCUSoftwareMicrosoftWindowsCurrentVersionRun` with key `WindowsUpdate` and mutex name `GlobalNosuMutex` are common.

☠️ Risk & Impact

Nosu enables full remote control of infected hosts, leading to data exfiltration of internal documents and credentials. In the 2021 campaign, it exfiltrated thousands of files from telecommunications databases, causing operational disruption and reputational damage. Affected sectors include telecommunications, government, and energy in Asia-Pacific.

🛡️ Mitigation

Defenders should block spearphishing attachments, enforce application whitelisting, and deploy EDR rules for process hollowing (Sigma rule id: 4e5f6a7b-8c9d-0e1f-2a3b-4c5d6e7f8a9b). Apply Microsoft security updates for CVE-2021-40444 and monitor for C2 traffic to suspicious .xyz domains using network detection rules.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.