Skip to main content
Mallory
Back to malware
MalwareUsed by 1 actor

NosyHistorian

NosyHistorian is a custom C#/.NET malware tool used by the China-aligned APT group LongNosedGoblin in cyber-espionage operations targeting government entities in Southeast Asia and Japan since at least 2023. It is one of the first tools deployed inside victim networks and is used to collect browser history from Google Chrome, Microsoft Edge, and Mozilla Firefox. The malware is described as having the internal name GetBrowserHistory. LongNosedGoblin has abused Windows Active Directory Group Policy to deploy malware, including NosyHistorian, across compromised networks and for lateral movement, implying access to Domain Controllers and domain administrator credentials. The stolen browsing-history data is used to understand user behavior, assess victim value, and decide which systems or users should receive follow-on malware. Only a small subset of NosyHistorian-affected victims were subsequently compromised with the NosyDoor backdoor. The content associates NosyHistorian specifically with LongNosedGoblin’s espionage activity against government networks. No standalone indicators of compromise for NosyHistorian are provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
LongNosedGoblin

"NosyGoblin's bespoke tooling also includes malware the ESET team named NosyHistorian used to snoop through browser history. If NosyHistorian determines the target is worth pursuing further, it drops a backdoor called NosyDoor"

via dark readingdarkreading.com
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

T1484.001Group Policy ModificationEvidence1

“LongNosedGoblin uses Group Policy to deploy malware across the compromised network…”

T1484.001Group Policy ModificationEvidence1

“LongNosedGoblin uses Group Policy to deploy malware across the compromised network…”

Discovery

1 technique
T1217Browser Information DiscoveryEvidence1
TacticDiscovery

“NosyHistorian, is used to gather browser history and decide where to deploy further malware…”

T1071.001Web ProtocolsEvidence1

“LongNosedGoblin… uses… Microsoft OneDrive and Google Drive as command and control (C&C) servers.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.