Skip to content

NanoCore

NanoCore RAT is a Windows-based remote access trojan used in criminal and intrusion activity to provide persistent remote control over compromised systems.

Profile source: Mallory opens in a new tab

NanoCore

Family profile

NanoCore RAT is a Windows-based remote access trojan used in criminal and intrusion activity to provide persistent remote control over compromised systems. It is commonly categorized as a commodity .NET RAT and has been observed alongside other widely used families such as AsyncRAT, Quasar RAT, Remcos RAT, and njRAT. NanoCore has been used by both financially motivated operators and state-linked actors seeking to blend into ordinary cybercrime traffic through use of publicly available malware.

Documented NanoCore capabilities include keylogging, collection of victim network information such as the host IP address, modification of the Windows Registry, and encrypted command-and-control communications using DES. It has also been observed establishing persistence through VBScript-based mechanisms, including creation of Registry RunOnce autorun entries to execute VBS scripts at user logon. These behaviors are consistent with post-compromise surveillance and long-term remote access on victim endpoints.

NanoCore has been distributed through phishing and spearphishing campaigns, including coronavirus-themed email lures, and has also appeared as a payload delivered by malware distribution systems and loaders such as GuLoader. Reporting also links it to broader malware-delivery ecosystems that distribute multiple commodity RATs. Infrastructure associated with NanoCore has appeared in abuse of cloud tunneling services for command-and-control concealment, and NanoCore samples have been observed communicating with malicious infrastructure embedded in repurposed expired domains.

Use of NanoCore has been associated with Iranian activity, including reporting that APT33 and IRGC-linked operators used NanoCore as an off-the-shelf RAT in campaigns targeting sectors such as aerospace, satellite technology, and international organizations. More broadly, NanoCore-related infrastructure has been observed reaching victims across sectors including education, government, healthcare, banking, and information technology. Its continued presence in commodity malware ecosystems and mixed criminal-state usage makes it a durable and widely recognized RAT family.

Capabilities

  • Keylogging
  • Persistence
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
21 IP / 368 hostnames

Leading locations

  • US264
  • DE8
  • NL8
  • SE5
  • SG3
  • RU2
  • FR1
  • HK1
  • KR1
  • MD1
  • PL1

Leading providers

  • Cloudflare, Inc.249
  • Amazon.com, Inc.5
  • Amazon.com, Inc.5
  • Bahnhof AB4
  • Omegatech LTD4
  • DEDIK SERVICES LIMITED3

Infrastructure traits

  • Hosting 290
  • Anycast 252
  • Proxy 3

Samples

Recent associated samples

Reported operators

Threat actors

12 named in public reporting
Sable Squirrel

к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT

APT33

APT33 is known to use publicly available remote access trojans (RATs) like Nanocore to blend in with normal cybercriminal activity and avoid the attribution which typically comes from the implementation of custom malware.

Water Basilisk

In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.

TA505

...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...

Vendetta

In addition to the nature of the backdoor virus, ReZer0 also carries known remote control Trojans such as NanoCore and Remcos in the resources.

Iranian Dark Coders Team

According to the indictment, one of the main malware tools used in the attacks was the Nanocore RAT (Trojan.Nancrat). Although it was publicly available, Symantec has observed Elfin make extensive use of Nanocore.

Gorgon Group

NanoCore (also known as Nancrat) is considered a RAT (Remote Admin Tool), which is used to obtain relevant information from victims such as data from the affected computer, camera captures, keyboard input, etc.

Aggah

NanoCore (also known as Nancrat) is considered a RAT (Remote Admin Tool), which is used to obtain relevant information from victims such as data from the affected computer, camera captures, keyboard input, etc.

TA2719

NanoCore (also known as Nancrat) is considered a RAT (Remote Admin Tool), which is used to obtain relevant information from victims such as data from the affected computer, camera captures, keyboard input, etc.

TA2722

NanoCore (also known as Nancrat) is considered a RAT (Remote Admin Tool), which is used to obtain relevant information from victims such as data from the affected computer, camera captures, keyboard input, etc.

SilverTerrier

With an average of 125 unique samples per month, NanoCore was the most frequently seen RAT employed by SilverTerrier actors in 2018.

Group5

"The malware downloaded and executed by the .Net downloader is NanoCore, a well-known RAT (Remote Access Trojan) that enables the remote monitoring of victims via their computers."

Exploited software

Vulnerabilities linked to NanoCore

4 CVEs

MITRE ATT&CK

NanoCore in ATT&CK

53 distinct techniques

Techniques

53 techniques

Reporting

Research mentioning NanoCore

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.