NosyDoor Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
May 5, 2026
Last Seen
May 21, 2026

NosyDoor is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.

NosyDoor is a malware family tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed May 5, 2026; most recent activity May 21, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Longnosedgoblin Tries Sniff Out Governmental Affairs Southeast Asia Japan — www.welivesecurity.com · May 21, 2026
  • Introducing Showboat: A new malware family taunts defenses and targets international telecom firms — Lumen · May 21, 2026
  • UAT — Blog.Talosintelligence · May 5, 2026

Frequently asked questions

What is NosyDoor?

NosyDoor is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.

Is NosyDoor still active?

The most recent intelligence report mentioning NosyDoor on ThreatCluster is dated May 21, 2026. Activity was first observed May 5, 2026, giving a tracked span from then to May 21, 2026.

What is NosyDoor associated with?

Across ThreatCluster reporting, NosyDoor most frequently co-occurs with Cl-sta-0049, Earth Estries, Earth Naga, Erudite Mogwai, Jewelbug, among 12 tracked related entities.

What are the latest developments involving NosyDoor?

The most significant recent cluster is “Showboat Malware Targets Telecoms in China-Aligned Cyber Espionage Campaign” (9 articles · Updated May 21, 2026). NosyDoor appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on NosyDoor?

NosyDoor appears in 3 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown