NosyStealer is a browser-data stealing malware used by the China-aligned APT group LongNosedGoblin in cyber-espionage operations targeting government entities in Japan and Southeast Asia since at least 2023. It is part of LongNosedGoblin's custom C#/.NET toolset and is used to exfiltrate data from Microsoft Edge and Google Chrome. Reported behavior includes exfiltrating Chrome and Edge data to Google Drive, including in the form of an encrypted TAR archive. ESET reported that NosyStealer has a four-stage execution chain, with the stealer as the final-stage payload, and that it uses Donut shellcode for in-memory execution. The malware is associated with broader LongNosedGoblin activity that abuses Windows Active Directory Group Policy for malware deployment and lateral movement. High-confidence targeting described in the reporting is focused on government networks in Southeast Asia and Japan. Cloud services, particularly Google Drive, are used for exfiltration, and one report also states that Google Docs is used for triggers and status messages.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...unknown malware on the victims' machines: NosyStealer, which exfiltrates browser data"
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware focused on exfiltrating browser data from victim systems.
NosyStealer is a tool designed to steal browser data from Microsoft Edge and Google Chrome, supporting the group's data theft objectives.
Stealer malware that exfiltrates browser data to Google Drive as encrypted archives.
Malware that exfiltrates browser data from infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.