NewCore

Malware type
rat, trojan
Profile updated
2026-07-07 15:13:32

Targeted industries: government-and-public-sector

Targeted regions: country_code:vn

Context

NewCore is a remote access trojan first discovered by Fortinet researchers while conducting analysis on a China-linked APT campaign targeting Vietnamese organizations. The trojan is a DLL file, executed after a trojan downloader is installed on the targeted machine. Based on strings in the code, the trojan may be compiled from the publicly-available source code of the PcClient and PcCortr backdoor trojans.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Newcore_Rat_Auto (yara-rule)

Reports & references

  • blog.fortinet.com — Rehashed Rat Used In Apt Campaign Against Vietnamese Organizations (report)
  • cyber.nj.gov — Newcore (report)

External references