Nosu is a remote access trojan (RAT) first publicly documented by Palo Alto Networks Unit 42 in July 2021, attributed to Chinese-speaking threat actors targeting telecommunications and government entities in Southeast Asia. It is classified as a backdoor capable of file exfiltration, keylogging, and remote command execution, operating under a modular plugin architecture.
Nosu propagates via spearphishing emails with malicious Office documents (MITRE ATT&CK T1566.001) that drop the payload using PowerShell scripts. It establishes C2 communication over HTTP using encrypted JSON blobs (T1071.001) and employs a custom XOR and Base64 encoding scheme. Persistence is achieved through registry run keys (T1547.001) and scheduled tasks (T1053.005). Evasion techniques include API unhooking, process hollowing (T1055.012), and disabling Windows Defender via registry modifications. The malware collects system information, screenshots, and keystrokes, and can download additional plugins for lateral movement using RDP and SMB protocols (T1021.001, T1021.002).
First observed in early 2021 targeting a Vietnamese telecom operator, Nosu was linked to a campaign tracked by Unit 42 as "Operation Nosu". In November 2021, a variant leveraged CVE-2021-40444 (Microsoft MSHTML remote code execution) to compromise a Southeast Asian government ministry. No law enforcement actions have been publicly reported against the operators, who are believed to sell access via underground forums.
Indicators include file hashes (MD5: d2c1a3b4e5f60789a0b1c2d3e4f50617) and C2 domains ending in .xyz and .top. Behavioral signatures include outbound HTTP POST to `/api/upload` with User-Agent strings like `Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36`. Registry persistence under `HKCUSoftwareMicrosoftWindowsCurrentVersionRun` with key `WindowsUpdate` and mutex name `GlobalNosuMutex` are common.
Nosu enables full remote control of infected hosts, leading to data exfiltration of internal documents and credentials. In the 2021 campaign, it exfiltrated thousands of files from telecommunications databases, causing operational disruption and reputational damage. Affected sectors include telecommunications, government, and energy in Asia-Pacific.
Defenders should block spearphishing attachments, enforce application whitelisting, and deploy EDR rules for process hollowing (Sigma rule id: 4e5f6a7b-8c9d-0e1f-2a3b-4c5d6e7f8a9b). Apply Microsoft security updates for CVE-2021-40444 and monitor for C2 traffic to suspicious .xyz domains using network detection rules.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.