NanoCore is a commercially available, .NET-based remote access trojan targeting Windows systems. It is used by cybercriminals and advanced threat actors to maintain unauthorized access, monitor users, and steal sensitive information. Its capabilities include keylogging, clipboard capture, collection of document-file information, and discovery of the infected host’s IP address. Captured keystrokes can expose usernames and passwords, including credentials for financial payment platforms. Observed variants upload stolen information through FTP and encrypt command-and-control traffic using DES.
NanoCore establishes persistence through Windows Registry modifications, including autostart entries that execute VBScript at user logon. Analyzed samples perform process injection and debugger detection. Some campaigns package the main .NET executable inside a heavily obfuscated AutoIt wrapper that reconstructs the payload during execution. NanoCore has also been delivered by the DarkTortilla crypter and loader. Operators have routed its command-and-control communications through ngrok tunnels.
Distribution includes phishing and malspam using invoice, coronavirus, and vaccine-related lures. Campaigns have delivered malicious executables inside ISO disk images and compressed RAR archives. Invoice-themed campaigns have included broadly distributed, apparently untargeted messages, while vaccine-themed attacks targeted government health agencies, universities with medical programs, and health insurers in the United States and Canada.
NanoCore is part of the toolsets used by APT33 and the financially motivated OPERA1ER group. OPERA1ER has used NanoCore keylogging to capture payment-backend credentials during intrusions into financial organizations, including deploying a command-and-control server inside a victim network before fraudulent transactions. NanoCore has also appeared in COVID-19-themed campaigns associated with the Nigerian cybercriminal ecosystem tracked as SilverTerrier.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When analyzing the organization’s CVE-2017-11882 exploit document, we found that the way to bypass the shellcode length limitation is similar to that used by the APT organization TA505... Unlike most previous CVE-2017-11882 exploits, Bayworld uses malicious code in xlsx files. | ...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
In February 2019, the group attempted to exploit a known vulnerability (CVE-2018-20250) in WinRAR in order to compromise an organization in the chemical sector in Saudi Arabia.
"The malware downloaded and executed by the .Net downloader is NanoCore, a well-known RAT (Remote Access Trojan) that enables the remote monitoring of victims via their computers."
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“A seventh campaign was launched spanning April 7th and 8th 2020, in which two samples of NanoCore RAT were packaged as compressed RAR files with a vaccine-related lure.”
“NanoCore provides a keylogging feature out of the box which has been used by the threat actor to steal back-end user’s login and password.”
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
APT33 is known to use publicly available remote access trojans (RATs) like Nanocore to blend in with normal cybercriminal activity and avoid the attribution which typically comes from the implementation of custom malware.
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The PowerPoint file contains a macro that leverages mshta to download the next stage payload from Pastebin. Auto_Close() in the macro ensures that the malicious code is executed only when the file is closed. | With the help of a macro, it downloads an encoded VBScript from Pastebin... The decoded script is a VBScript.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
The FBI observed these actors conducting follow-on activities to expand and maintain their unauthorized access, such as creating additional backdoors and escalating privileges.
The content lists HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce, RunOnceEx, and examples such as reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\0001\Depend /v 1 /d "C:\temp\evil[.]dll". | The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
“The main payload... injects it into a subprocess. The payload itself stays in memory.”
The content lists HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce, RunOnceEx, and examples such as reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\0001\Depend /v 1 /d "C:\temp\evil[.]dll". | The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
NanoCore RAT ... Also used to record user credentials and conduct surveillance using infected computers.
часть инфраструктуры Sable Squirrel используется для работы малвари: к доменам хак-группы обращались более 31 000 образцов вредоносов... некоторые сайты одновременно показывали посетителям спортивные трансляции и работали в качестве управляющих серверов для малвари.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
APT33 is known to use publicly available remote access trojans (RATs) like Nanocore to blend in with normal cybercriminal activity and avoid the attribution which typically comes from the implementation of custom malware.
311 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
109 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access malware represented among samples communicating with Sable Squirrel-controlled command-and-control infrastructure.
A remote-access-trojan payload explicitly identified as delivered by DarkTortilla.
Remote access trojan listed as one of the malware families communicating with Sable Squirrel-controlled domains.
Remote access trojan observed communicating with Sable Squirrel infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.