We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Win32/Nsag
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
Windows Defender Antivirus detects and removes this threat.
Win32/Nsag is a family of data-stealing trojans. A Win32/Nsag trojan is created when certain malicious software injects code into wininet.dll, a Windows system file. When a user tries to send data to a website, code in Win32/Nsag may cause code in other malicious software on the computer to capture the user data and send it to an attacker.