NewCore
- Malware type
- rat, trojan
- Profile updated
- 2026-07-07 15:13:32
Targeted industries: government-and-public-sector
Targeted regions: country_code:vn
Context
NewCore is a remote access trojan first discovered by Fortinet researchers while conducting analysis on a China-linked APT campaign targeting Vietnamese organizations. The trojan is a DLL file, executed after a trojan downloader is installed on the targeted machine. Based on strings in the code, the trojan may be compiled from the publicly-available source code of the PcClient and PcCortr backdoor trojans.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Newcore_Rat_Auto (yara-rule)
Reports & references
- blog.fortinet.com — Rehashed Rat Used In Apt Campaign Against Vietnamese Organizations (report)
- cyber.nj.gov — Newcore (report)