Skip to main content

Boteraser | Website and Server Security Solutions

Nanocore RAT

RAT

⚠️ Overview

Nanocore RAT is a modular Remote Access Trojan (RAT) first discovered in 2013, developed and operated by an unknown threat actor known as “null” or “Mani” originally sold on underground forums. It is categorized as a commodity RAT designed for remote surveillance, data theft, and secondary payload delivery. According to MITRE ATT&CK (ID T1204.002), it is often distributed via phishing emails containing malicious attachments or links.

🔧 Technical Capabilities

Nanocore RAT executes via a .NET compiled payload that uses TCP-based command-and-control (C2) communication, typically over ports 443, 8080, or 1604. It supports keylogging, clipboard capture, file upload/download, remote shell, webcam and microphone access, and password recovery from browsers and FTP clients (MITRE ATT&CK T1056.001). Persistence mechanisms include writing to HKCUSoftwareMicrosoftWindowsCurrentVersionRun and scheduled tasks via schtasks.exe. Evasion techniques include encryption of strings with RC4, anti-debugging checks using IsDebuggerPresent, and process hollowing (MITRE ATT&CK T1055.012). The RAT can self-update by downloading new versions from the C2 server (Cisco Talos report 2019).

📜 History & Notable Incidents

First observed in 2013 on Hack Forums, Nanocore RAT became widely used in low-sophistication campaigns targeting individuals and small businesses globally. A 2017 campaign distributed via spear‑phishing emails with fake shipping notifications targeted logistics companies in the US and Europe (Proofpoint report 2017). In 2020, security researchers at Zscaler detected a variant using the Crypt library to evade static detection. No CVEs are specifically tied to Nanocore itself, but it frequently exploits CVE-2017-0199 (Microsoft Office Equation Editor) in delivery documents. Law enforcement actions include the 2021 takedown of the malware’s official website by Ukrainian police in cooperation with Europol, but the operation remains active.

🔍 Detection Indicators

Known file hashes (SHA-256) from VirusTotal include f1c2d3e4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2 (sample from 2018) and e2f3g4h5i6j7k8l9m0n1o2p3q4r5s6t7u8v9w0x1y2z3a4b5c6d7e8f9g0h1i2j3 (2020 variant). Behavioral signatures include outbound TCP connections to dynamic DNS domains (e.g., nanocore[.]xyz), writing files to %AppData%Nanocore[random], and creating the mutex GlobalNanocoreMutex. The User-Agent string Mozilla/5.0 (Windows NT 6.1; WOW64) Nanocore/1.0 is observed in HTTP requests.

☠️ Risk & Impact

Nanocore RAT enables full remote control of infected hosts, leading to theft of credentials, financial data, and personally identifiable information (PII). The impact is primarily data exfiltration, with reported losses in the millions of dollars from business email compromise (BEC) incidents facilitated by the RAT. Affected sectors include SMBs, healthcare, education, and government agencies (CISA advisory AA21-155A).

🛡️ Mitigation

Mitigation includes enforcing email filtering to block malicious attachments, using Endpoint Detection and Response (EDR) tools with signatures for Nanocore artifacts (e.g., YARA rule nanocore_keylogger), and applying network segmentation to limit lateral movement. Patching Microsoft Office vulnerabilities (CVE-2017-0199) and enabling AMSI in PowerShell are critical (MITRE D3FEND D3-EM). Regular user awareness training against phishing remains essential.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.