NanoCore

S0336

Malware.View on attack.mitre.org

About this malware

NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information. It has been used by threat actors since 2013.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1016
System Network Configuration Discovery

NanoCore gathers the IP address from the victim’s machine.

T1027
Obfuscated Files or Information

NanoCore’s plugins were obfuscated with Eazfuscater.NET 3.3.

T1056.001
Keylogging

NanoCore can perform keylogging on the victim’s machine.

T1059.003
Windows Command Shell

NanoCore can open a remote command-line interface and execute commands. NanoCore uses JavaScript files.

T1059.005
Visual Basic

NanoCore uses VBS files.

T1105
Ingress Tool Transfer

NanoCore has the capability to download and activate additional modules for execution.

T1112
Modify Registry

NanoCore has the capability to edit the Registry.

T1123
Audio Capture

NanoCore can capture audio feeds from the system.

T1125
Video Capture

NanoCore can access the victim's webcam and capture data.

T1547.001
Registry Run Keys / Startup Folder

NanoCore creates a RunOnce key in the Registry to execute its VBS scripts each time the user logs on to the machine.

T1573.001
Symmetric Cryptography

NanoCore uses DES to encrypt the C2 traffic.

T1685
Disable or Modify Tools

NanoCore can modify the victim's anti-virus.

T1686
Disable or Modify System Firewall

NanoCore can modify the victim's firewall.

Groups that use it4

Campaigns0

None recorded.

References4

  1. Cofense NanoCore Mar 2018 Open source
    Patel, K. (2018, March 02). The NanoCore RAT Has Resurfaced From the Sewers. Retrieved September 25, 2024.
  2. DigiTrust NanoCore Jan 2017 Open source
    The DigiTrust Group. (2017, January 01). NanoCore Is Not Your Average RAT. Retrieved November 9, 2018.
  3. PaloAlto NanoCore Feb 2016 Open source
    Kasza, A., Halfpop, T. (2016, February 09). NanoCoreRAT Behind an Increase in Tax-Themed Phishing E-mails. Retrieved November 9, 2018.
  4. Unit 42 Gorgon Group Aug 2018 Open source
    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.