NanoCore

MITRE ATT&CK: S0336 View on attack.mitre.org

Aliases: NanoCore

First seen
2013-01-01 00:00:00
Malware type
rat, keylogger, screen-capture, spyware
Family
Malware family
Operating systems
windows
Related IoCs
8477 (7325 malicious)
Last IoC activity
2026-09-02 04:03:57
Profile updated
2026-07-07 13:18:57

Targeted industries: education-and-nonprofits financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing retail-and-hospitality

Context

NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information. It has been used by threat actors since 2013.

Recent IoC activity

7,405 malicious indicators in Maltiverse are attributed to NanoCore (S0336). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample wolkafashion.pl_ransome.exe 2026-09-03 1
file sample wolkafashion.pl_new.exe 2026-09-03 1
file sample 2026-09-02_53e32fd211bb7c0a68bd7aa1edd26100_cobalt-strike_coinminer_darkgate_... 2026-09-03 1
IP address 3.64.4.198 2026-09-03 4
IP address 3.127.253.86 2026-09-03 4
IP address 3.69.115.178 2026-09-03 4
IP address 3.68.171.119 2026-09-03 4
IP address 3.127.181.115 2026-09-03 4
IP address 3.126.224.214 2026-09-03 4
file sample sample-de293039311f.exe 2026-09-03 2
file sample sample-8894afe564c0.exe 2026-09-03 2
file sample sample-ce79db962ecd.exe 2026-09-03 2
hostname nas231.duckdns.org 2026-09-03 1
hostname nuttara2020.ddns.net 2026-09-03 3
hostname kcfresh.duckdns.org 2026-09-03 1
hostname goodluckwar.duckdns.org 2026-09-03 2
hostname isiefinama.duckdns.org 2026-09-03 1
hostname dbep.duckdns.org 2026-09-03 2
hostname grace147.ddns.net 2026-09-03 1
hostname us3.localto.net 2026-09-03 1

Detection coverage

  • 1 YARA rules
  • 497 Sigma rules

Malware & tools used

  • Ingress Tool Transfer (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Video Capture (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Audio Capture (attack-pattern)
  • Disable or Modify System Firewall (attack-pattern)
  • Visual Basic (attack-pattern)
  • Keylogging (attack-pattern)
  • Modify Registry (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_MALWARE_Win_Nanocore (yara-rule)

Reports & references

  • researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
  • MITRE ATT&CK — S0336 (report)
  • researchcenter.paloaltonetworks.com — Nanocorerat Behind An Increase In Tax Themed Phishing E Mails (report)
  • web.archive.org — Nanocore Rat Resurfaced Sewers (report)
  • digitrustgroup.com — Nanocore Not Your Average Rat (report)

External references