Nosu

Malware type
credential-stealer
Family
Malware family
Profile updated
2026-07-07 14:54:50

Targeted regions: country_code:us country_code:br country_code:mx country_code:sg country_code:id country_code:th

Context

According to PCrisk, Nosu is the name of a malicious program classified as a stealer. This malware is designed to steal information from infected machines. The Nosu stealer can extract a wide variety of data from devices and installed applications. The most active campaigns associated with Nosu were noted in North and South America, as well as Southeast Asia.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Infostealer_Win_Nosu (yara-rule)
  • MALPEDIA_Win_Nosu_Auto (yara-rule)

Reports & references

  • bitsight.com — Cova And Nosu New Loader Spreads New Stealer (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Nosu (report)

External references