Nanocore RAT

Aliases: Nancrat, NanoCore

First seen
2013-12-01 00:00:00
Malware type
rat, credential-stealer, spyware
Family
Malware family
Last IoC activity
2026-07-22 04:21:36
Profile updated
2026-07-07 12:42:25

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical education-and-nonprofits

Context

Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras. It as been used for a while by numerous criminal actors as well as by nation state threat actors.

Detection coverage

  • 1 YARA rules

Used by threat actors

Exploited vulnerabilities

  • CVE-2023-38831 (vulnerability)

Detection rules

  • DITEKSHEN_MALWARE_Win_Nanocore (yara-rule)

Reports & references

  • Mandiant — Apt33 Insights Into Iranian Cyber Espionage (report)
  • Broadcom/Symantec — Elfin Apt33 Espionage (report)
  • secureworks.com — Cobalt Trinity (report)
  • proofpoint.com — New Threat Actor Spoofs Philippine Government Covid 19 Health Data Widespread (report)
  • proofpoint.com — Threat Actor Profile Ta2719 Uses Colorful Lures Deliver Rats Local Languages (report)
  • researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
  • Broadcom/Symantec — Elfin Apt33 Espionage (report)
  • CISA — Aa20 345A (report)
  • intel471.com — Privateloader Malware (report)
  • assets.virustotal.com — 2021Trends (report)
  • intezer.com — Intezer 2020 Go Malware Round Up (report)
  • blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
  • info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
  • research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)
  • mp.weixin.qq.com — Mstwbmks0G3Et4Goji2Mwa (report)
  • Cisco Talos — 2020 Year In Malware (report)
  • cisecurity.org — Top 10 Malware March 2022 (report)
  • spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
  • Trend Micro — Ssl Tls Technical Brief (report)
  • labs.bitdefender.com — 5 Times More Coronavirus Themed Malware Reports During March (report)
  • proofpoint.com — New Whiteshadow Downloader Uses Microsoft Sql Retrieve Malware (report)
  • ciphertechsolutions.com — Roboski Global Recovery Automation (report)
  • securityintelligence.com — Roboski Global Recovery Automation (report)
  • blog.cluster25.duskrise.com — Cve 2023 38831 Russian Attack (report)

External references