Remote Access Trojan
NanoCore
First seen: 2013-01 • Status: active
Currently Active Threat
NanoCore is a powerful spy tool that was sold commercially until the creator got caught.
Overview
NanoCore is a commercial RAT whose creator was arrested but source code leaked.
Also Known As
Nanocore RAT
How It Spreads
- • Phishing emails
- • Malicious documents
- • Exploit kits
What It Does
- • Remote control
- • Keylogging
- • Password theft
- • File exfiltration
Is your business exposed?
Target Platforms
Windows
Detection Tips
- • Monitor for RAT plugins
- • Detect C2 patterns
MITRE ATT&CK Techniques
T1566, T1059, T1056
If You're Infected
- 1.
Isolate and reimage infected systems
Related Malware
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required