NanoCore RAT is a Windows-based remote access trojan used in criminal and intrusion activity to provide persistent remote control over compromised systems. It is commonly categorized as a commodity .NET RAT and has been observed alongside other widely used families such as AsyncRAT, Quasar RAT, Remcos RAT, and njRAT. NanoCore has been used by both financially motivated operators and state-linked actors seeking to blend into ordinary cybercrime traffic through use of publicly available malware.
Documented NanoCore capabilities include keylogging, collection of victim network information such as the host IP address, modification of the Windows Registry, and encrypted command-and-control communications using DES. It has also been observed establishing persistence through VBScript-based mechanisms, including creation of Registry RunOnce autorun entries to execute VBS scripts at user logon. These behaviors are consistent with post-compromise surveillance and long-term remote access on victim endpoints.
NanoCore has been distributed through phishing and spearphishing campaigns, including coronavirus-themed email lures, and has also appeared as a payload delivered by malware distribution systems and loaders such as GuLoader. Reporting also links it to broader malware-delivery ecosystems that distribute multiple commodity RATs. Infrastructure associated with NanoCore has appeared in abuse of cloud tunneling services for command-and-control concealment, and NanoCore samples have been observed communicating with malicious infrastructure embedded in repurposed expired domains.
Use of NanoCore has been associated with Iranian activity, including reporting that APT33 and IRGC-linked operators used NanoCore as an off-the-shelf RAT in campaigns targeting sectors such as aerospace, satellite technology, and international organizations. More broadly, NanoCore-related infrastructure has been observed reaching victims across sectors including education, government, healthcare, banking, and information technology. Its continued presence in commodity malware ecosystems and mixed criminal-state usage makes it a durable and widely recognized RAT family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When analyzing the organization’s CVE-2017-11882 exploit document, we found that the way to bypass the shellcode length limitation is similar to that used by the APT organization TA505... Unlike most previous CVE-2017-11882 exploits, Bayworld uses malicious code in xlsx files. | ...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
In February 2019, the group attempted to exploit a known vulnerability (CVE-2018-20250) in WinRAR in order to compromise an organization in the chemical sector in Saudi Arabia.
"The malware downloaded and executed by the .Net downloader is NanoCore, a well-known RAT (Remote Access Trojan) that enables the remote monitoring of victims via their computers."
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
APT33 is known to use publicly available remote access trojans (RATs) like Nanocore to blend in with normal cybercriminal activity and avoid the attribution which typically comes from the implementation of custom malware.
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
In addition to the nature of the backdoor virus, ReZer0 also carries known remote control Trojans such as NanoCore and Remcos in the resources.
According to the indictment, one of the main malware tools used in the attacks was the Nanocore RAT (Trojan.Nancrat). Although it was publicly available, Symantec has observed Elfin make extensive use of Nanocore.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
This report details a specific phishing campaign used to distribute the Agent Tesla RAT. The lure in the emails is centered around updates to COVID-specific PPE.
Crimson is typically delivered to the victim via a phishing email containing a malicious .doc file or link to a malicious executable.
In one instance, the actors were observed hosting malicious code on a file-sharing service registered in the name of a US company employee, and including links to that malicious code in spear-phishing emails. One of the actors was observed using a fraudulent domain to host malware, then sending a link to the malware via spear phishing.
It creates a scheduled task with the name Pornhub. This task leverages mshta to download the next stage payload from Pastebin as well.
The final stage is an obfuscated PowerShell script that contains the payloads and is responsible for deobfuscating and injecting them into the assigned process.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The PowerPoint file contains a macro that leverages mshta to download the next stage payload from Pastebin. Auto_Close() in the macro ensures that the malicious code is executed only when the file is closed. | With the help of a macro, it downloads an encoded VBScript from Pastebin... The decoded script is a VBScript.
Examples include Cobalt Group using a JavaScript backdoor to launch cmd.exe, NanoCore using JavaScript files, Orz executing commands with JavaScript, Patchwork using JavaScript code, and SQLRat executing JavaScript on the host system.
It creates a scheduled task with the name Pornhub. This task leverages mshta to download the next stage payload from Pastebin as well.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
The FBI observed these actors conducting follow-on activities to expand and maintain their unauthorized access, such as creating additional backdoors and escalating privileges.
The content lists HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce, RunOnceEx, and examples such as reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\0001\Depend /v 1 /d "C:\temp\evil[.]dll". | The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
It creates a scheduled task with the name Pornhub. This task leverages mshta to download the next stage payload from Pastebin as well.
The content lists HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce, RunOnceEx, and examples such as reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\0001\Depend /v 1 /d "C:\temp\evil[.]dll". | The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
NanoCore RAT ... Also used to record user credentials and conduct surveillance using infected computers.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
часть инфраструктуры Sable Squirrel используется для работы малвари: к доменам хак-группы обращались более 31 000 образцов вредоносов... некоторые сайты одновременно показывали посетителям спортивные трансляции и работали в качестве управляющих серверов для малвари.
Almost one-third of prevalent malware families we recently analyzed support communication over non-HTTP/S protocols.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
311 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
102 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan listed as one of the malware families communicating with Sable Squirrel-controlled domains.
Remote access trojan observed communicating with Sable Squirrel infrastructure.
Remote access trojan identified in samples using Sable Squirrel domain infrastructure for control traffic.
Remote access trojan observed among malware samples using Sable Squirrel domains as C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.