NanoCore RAT is a Windows-focused commodity remote access trojan written for the .NET ecosystem and widely used in cybercrime operations as a general-purpose backdoor and surveillance tool. It has been observed in malware distribution chains alongside other commodity RATs and stealers, and has been used both by financially motivated operators and by state-linked actors seeking to blend into ordinary criminal traffic. Public reporting has linked its use to campaigns involving Iranian operators and to broader criminal infrastructures that also supported families such as AsyncRAT, Quasar RAT, Remcos RAT, and njRAT.
NanoCore provides interactive remote access to infected systems and supports host reconnaissance and user monitoring. Documented capabilities include keylogging, collection of victim network information such as the host IP address, and modification of the Windows Registry. It has also been observed using DES to encrypt command-and-control traffic. For persistence, NanoCore has been documented creating Registry RunOnce-based execution for VBS scripts at user logon, indicating use of script-based autostart mechanisms on compromised hosts.
Distribution has commonly relied on phishing and malspam, including coronavirus-themed email campaigns and broader spam operations using social-engineering lures. NanoCore has also appeared as a secondary payload delivered by malware loaders such as GuLoader. Operationally, it has been seen using cloud tunneling services such as ngrok to conceal command-and-control infrastructure, and it has been identified communicating with large criminal domain ecosystems that mixed malware C2 with other illicit online services.
NanoCore primarily targets Microsoft Windows systems and is best characterized as a commodity RAT/backdoor used for remote control, surveillance, persistence, and post-compromise host interaction.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When analyzing the organization’s CVE-2017-11882 exploit document, we found that the way to bypass the shellcode length limitation is similar to that used by the APT organization TA505... Unlike most previous CVE-2017-11882 exploits, Bayworld uses malicious code in xlsx files. | ...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
In February 2019, the group attempted to exploit a known vulnerability (CVE-2018-20250) in WinRAR in order to compromise an organization in the chemical sector in Saudi Arabia.
"The malware downloaded and executed by the .Net downloader is NanoCore, a well-known RAT (Remote Access Trojan) that enables the remote monitoring of victims via their computers."
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
No less than 31,000 malware samples, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, and artifacts bearing HiddenTear ransomware signatures, have communicated with Sable Squirrel's infrastructure.
APT33 is known to use publicly available remote access trojans (RATs) like Nanocore to blend in with normal cybercriminal activity and avoid the attribution which typically comes from the implementation of custom malware.
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
In addition to the nature of the backdoor virus, ReZer0 also carries known remote control Trojans such as NanoCore and Remcos in the resources.
According to the indictment, one of the main malware tools used in the attacks was the Nanocore RAT (Trojan.Nancrat). Although it was publicly available, Symantec has observed Elfin make extensive use of Nanocore.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
This report details a specific phishing campaign used to distribute the Agent Tesla RAT. The lure in the emails is centered around updates to COVID-specific PPE.
Crimson is typically delivered to the victim via a phishing email containing a malicious .doc file or link to a malicious executable.
In one instance, the actors were observed hosting malicious code on a file-sharing service registered in the name of a US company employee, and including links to that malicious code in spear-phishing emails. One of the actors was observed using a fraudulent domain to host malware, then sending a link to the malware via spear phishing.
It creates a scheduled task with the name Pornhub. This task leverages mshta to download the next stage payload from Pastebin as well.
The final stage is an obfuscated PowerShell script that contains the payloads and is responsible for deobfuscating and injecting them into the assigned process.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The PowerPoint file contains a macro that leverages mshta to download the next stage payload from Pastebin. Auto_Close() in the macro ensures that the malicious code is executed only when the file is closed. | With the help of a macro, it downloads an encoded VBScript from Pastebin... The decoded script is a VBScript.
Examples include Cobalt Group using a JavaScript backdoor to launch cmd.exe, NanoCore using JavaScript files, Orz executing commands with JavaScript, Patchwork using JavaScript code, and SQLRat executing JavaScript on the host system.
It creates a scheduled task with the name Pornhub. This task leverages mshta to download the next stage payload from Pastebin as well.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
The FBI observed these actors conducting follow-on activities to expand and maintain their unauthorized access, such as creating additional backdoors and escalating privileges.
The content lists HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce, RunOnceEx, and examples such as reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\0001\Depend /v 1 /d "C:\temp\evil[.]dll". | The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
It creates a scheduled task with the name Pornhub. This task leverages mshta to download the next stage payload from Pastebin as well.
The content lists HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce, RunOnceEx, and examples such as reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\0001\Depend /v 1 /d "C:\temp\evil[.]dll". | The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
NanoCore RAT ... Also used to record user credentials and conduct surveillance using infected computers.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
A subset of the streaming domains also function as malware command-and-control (C2), even as they continue to present live streaming content to visitors.
Almost one-third of prevalent malware families we recently analyzed support communication over non-HTTP/S protocols.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
311 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
101 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan observed communicating with Sable Squirrel infrastructure.
Remote access trojan identified in samples using Sable Squirrel domain infrastructure for control traffic.
Remote access trojan observed among malware samples using Sable Squirrel domains as C2 infrastructure.
Mentioned as another malware family seen in adjacent spam campaigns alongside Vidar.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.