Malware.View on attack.mitre.org
NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information. It has been used by threat actors since 2013.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
NanoCore gathers the IP address from the victim’s machine. |
| T1027 Obfuscated Files or Information |
NanoCore’s plugins were obfuscated with Eazfuscater.NET 3.3. |
| T1056.001 Keylogging |
NanoCore can perform keylogging on the victim’s machine. |
| T1059.003 Windows Command Shell |
NanoCore can open a remote command-line interface and execute commands. NanoCore uses JavaScript files. |
| T1059.005 Visual Basic |
NanoCore uses VBS files. |
| T1105 Ingress Tool Transfer |
NanoCore has the capability to download and activate additional modules for execution. |
| T1112 Modify Registry |
NanoCore has the capability to edit the Registry. |
| T1123 Audio Capture |
NanoCore can capture audio feeds from the system. |
| T1125 Video Capture |
NanoCore can access the victim's webcam and capture data. |
| T1547.001 Registry Run Keys / Startup Folder |
NanoCore creates a RunOnce key in the Registry to execute its VBS scripts each time the user logs on to the machine. |
| T1573.001 Symmetric Cryptography |
NanoCore uses DES to encrypt the C2 traffic. |
| T1685 Disable or Modify Tools |
NanoCore can modify the victim's anti-virus. |
| T1686 Disable or Modify System Firewall |
NanoCore can modify the victim's firewall. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.