NanoCore
MITRE ATT&CK: S0336 View on attack.mitre.org
Aliases: NanoCore
- First seen
- 2013-01-01 00:00:00
- Malware type
- rat, keylogger, screen-capture, spyware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 8477 (7325 malicious)
- Last IoC activity
- 2026-09-02 04:03:57
- Profile updated
- 2026-07-07 13:18:57
Targeted industries: education-and-nonprofits financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing retail-and-hospitality
Context
NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information. It has been used by threat actors since 2013.
Recent IoC activity
7,405 malicious indicators in Maltiverse are attributed to NanoCore (S0336). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | wolkafashion.pl_ransome.exe | 2026-09-03 | 1 |
| file sample | wolkafashion.pl_new.exe | 2026-09-03 | 1 |
| file sample | 2026-09-02_53e32fd211bb7c0a68bd7aa1edd26100_cobalt-strike_coinminer_darkgate_... | 2026-09-03 | 1 |
| IP address | 3.64.4.198 | 2026-09-03 | 4 |
| IP address | 3.127.253.86 | 2026-09-03 | 4 |
| IP address | 3.69.115.178 | 2026-09-03 | 4 |
| IP address | 3.68.171.119 | 2026-09-03 | 4 |
| IP address | 3.127.181.115 | 2026-09-03 | 4 |
| IP address | 3.126.224.214 | 2026-09-03 | 4 |
| file sample | sample-de293039311f.exe | 2026-09-03 | 2 |
| file sample | sample-8894afe564c0.exe | 2026-09-03 | 2 |
| file sample | sample-ce79db962ecd.exe | 2026-09-03 | 2 |
| hostname | nas231.duckdns.org | 2026-09-03 | 1 |
| hostname | nuttara2020.ddns.net | 2026-09-03 | 3 |
| hostname | kcfresh.duckdns.org | 2026-09-03 | 1 |
| hostname | goodluckwar.duckdns.org | 2026-09-03 | 2 |
| hostname | isiefinama.duckdns.org | 2026-09-03 | 1 |
| hostname | dbep.duckdns.org | 2026-09-03 | 2 |
| hostname | grace147.ddns.net | 2026-09-03 | 1 |
| hostname | us3.localto.net | 2026-09-03 | 1 |
Detection coverage
- 1 YARA rules
- 497 Sigma rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Video Capture (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Audio Capture (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
- Visual Basic (attack-pattern)
- Keylogging (attack-pattern)
- Modify Registry (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
Used by threat actors
- Gorgon Group (threat-actor)
- APT33 (threat-actor)
- Group5 (threat-actor)
- SilverTerrier (threat-actor)
Detection rules
- DITEKSHEN_MALWARE_Win_Nanocore (yara-rule)
Reports & references
- researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
- MITRE ATT&CK — S0336 (report)
- researchcenter.paloaltonetworks.com — Nanocorerat Behind An Increase In Tax Themed Phishing E Mails (report)
- web.archive.org — Nanocore Rat Resurfaced Sewers (report)
- digitrustgroup.com — Nanocore Not Your Average Rat (report)