NosyDownloader
- First seen
- 2021-08-15 00:00:00
- Malware type
- downloader
- Profile updated
- 2026-07-07 13:16:48
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:us country_code:ru
Context
According to ESET Research, this malware is used by LongNosedGoblin and executes a chain of obfuscated commands passed to a spawned PowerShell process as one long command line argument, meaning that the script is not stored on disk. Every subsequent stage is encoded with base64, where the last one is additionally deflated with gzip. The second stage bypasses AMSI. In this case, NosyDownloader uses Matt Graeber’s reflection method and disabling script logging techniques made available on GitHub to bypass AMSI.
Reports & references
- botcrawl.com — Chinese Apt Longnosedgoblin Targets Government Networks In Southeast Asia And Japan (report)
- malpedia.caad.fkie.fraunhofer.de — Ps1.Nosy Downloader (report)
- ESET — Longnosedgoblin Tries Sniff Out Governmental Affairs Southeast Asia Japan (report)