Nanocore RAT
Aliases: Nancrat, NanoCore
- First seen
- 2013-12-01 00:00:00
- Malware type
- rat, credential-stealer, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:21:36
- Profile updated
- 2026-07-07 12:42:25
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical education-and-nonprofits
Context
Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras. It as been used for a while by numerous criminal actors as well as by nation state threat actors.
Detection coverage
- 1 YARA rules
Used by threat actors
- TA2536 (threat-actor)
Exploited vulnerabilities
- CVE-2023-38831 (vulnerability)
Detection rules
- DITEKSHEN_MALWARE_Win_Nanocore (yara-rule)
Reports & references
- Mandiant — Apt33 Insights Into Iranian Cyber Espionage (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- secureworks.com — Cobalt Trinity (report)
- proofpoint.com — New Threat Actor Spoofs Philippine Government Covid 19 Health Data Widespread (report)
- proofpoint.com — Threat Actor Profile Ta2719 Uses Colorful Lures Deliver Rats Local Languages (report)
- researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- CISA — Aa20 345A (report)
- intel471.com — Privateloader Malware (report)
- assets.virustotal.com — 2021Trends (report)
- intezer.com — Intezer 2020 Go Malware Round Up (report)
- blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
- info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)
- mp.weixin.qq.com — Mstwbmks0G3Et4Goji2Mwa (report)
- Cisco Talos — 2020 Year In Malware (report)
- cisecurity.org — Top 10 Malware March 2022 (report)
- spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
- Trend Micro — Ssl Tls Technical Brief (report)
- labs.bitdefender.com — 5 Times More Coronavirus Themed Malware Reports During March (report)
- proofpoint.com — New Whiteshadow Downloader Uses Microsoft Sql Retrieve Malware (report)
- ciphertechsolutions.com — Roboski Global Recovery Automation (report)
- securityintelligence.com — Roboski Global Recovery Automation (report)
- blog.cluster25.duskrise.com — Cve 2023 38831 Russian Attack (report)