Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 21 IP / 368 hostnames
NanoCore RAT is a Windows-based remote access trojan used in criminal and intrusion activity to provide persistent remote control over compromised systems.
Profile source: Mallory opens in a new tabNanoCore
NanoCore RAT is a Windows-based remote access trojan used in criminal and intrusion activity to provide persistent remote control over compromised systems. It is commonly categorized as a commodity .NET RAT and has been observed alongside other widely used families such as AsyncRAT, Quasar RAT, Remcos RAT, and njRAT. NanoCore has been used by both financially motivated operators and state-linked actors seeking to blend into ordinary cybercrime traffic through use of publicly available malware.
Documented NanoCore capabilities include keylogging, collection of victim network information such as the host IP address, modification of the Windows Registry, and encrypted command-and-control communications using DES. It has also been observed establishing persistence through VBScript-based mechanisms, including creation of Registry RunOnce autorun entries to execute VBS scripts at user logon. These behaviors are consistent with post-compromise surveillance and long-term remote access on victim endpoints.
NanoCore has been distributed through phishing and spearphishing campaigns, including coronavirus-themed email lures, and has also appeared as a payload delivered by malware distribution systems and loaders such as GuLoader. Reporting also links it to broader malware-delivery ecosystems that distribute multiple commodity RATs. Infrastructure associated with NanoCore has appeared in abuse of cloud tunneling services for command-and-control concealment, and NanoCore samples have been observed communicating with malicious infrastructure embedded in repurposed expired domains.
Use of NanoCore has been associated with Iranian activity, including reporting that APT33 and IRGC-linked operators used NanoCore as an off-the-shelf RAT in campaigns targeting sectors such as aerospace, satellite technology, and international organizations. More broadly, NanoCore-related infrastructure has been observed reaching victims across sectors including education, government, healthcare, banking, and information technology. Its continued presence in commodity malware ecosystems and mixed criminal-state usage makes it a durable and widely recognized RAT family.
C2 tracking
Derp observations, rolling seven-day window
Samples
040fc9205dd81fea2d34a0020c4485a8cafc15b9b31016244f6cb4dbf768e311 2c303b28f3f1cdd45121273e0905bcfd3d03e78c242a168be33f538e611eb3ef 3a8ebdbc7ade5de588bd1e6ab1b286af1da9524c53f0c41f7d26e7ac6fbebe62 b339391ea5029bff0a83bb4c86efce50d388056d138ba97ecf8b6da51c53e0c8 efdfd05a4f2b3cc05beca40603e375af74ae1dbe369da818d19206fcea00bb4f 2c80b32e3f47c70ca0eaa53b169a8d7ff6fb13844a61e538ab0dda4374baa600 36057a4f44b9aa863c2694833ba2af76bd0f4d873079aec02bcd6d2d5a468009 5f10ffa5d0b24fb46bbb845f66ddce79b9c87d355de4282c49de4b8e8e456674 cd4089d3fb91f7873ee1883a7c453335246d3d50b0530c0043463c2e61e3d08c f16f603022a036e5fc4b86eafe368f66757ed353e87be66da58772a4ba7558b6 Reported operators
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
APT33 is known to use publicly available remote access trojans (RATs) like Nanocore to blend in with normal cybercriminal activity and avoid the attribution which typically comes from the implementation of custom malware.
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
In addition to the nature of the backdoor virus, ReZer0 also carries known remote control Trojans such as NanoCore and Remcos in the resources.
According to the indictment, one of the main malware tools used in the attacks was the Nanocore RAT (Trojan.Nancrat). Although it was publicly available, Symantec has observed Elfin make extensive use of Nanocore.
NanoCore (also known as Nancrat) is considered a RAT (Remote Admin Tool), which is used to obtain relevant information from victims such as data from the affected computer, camera captures, keyboard input, etc.
NanoCore (also known as Nancrat) is considered a RAT (Remote Admin Tool), which is used to obtain relevant information from victims such as data from the affected computer, camera captures, keyboard input, etc.
NanoCore (also known as Nancrat) is considered a RAT (Remote Admin Tool), which is used to obtain relevant information from victims such as data from the affected computer, camera captures, keyboard input, etc.
NanoCore (also known as Nancrat) is considered a RAT (Remote Admin Tool), which is used to obtain relevant information from victims such as data from the affected computer, camera captures, keyboard input, etc.
With an average of 125 unique samples per month, NanoCore was the most frequently seen RAT employed by SilverTerrier actors in 2018.
"The malware downloaded and executed by the .Net downloader is NanoCore, a well-known RAT (Remote Access Trojan) that enables the remote monitoring of victims via their computers."
Exploited software
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.