Netskope Threat Labs

NanoCore

ATP Sandbox Adv. HeuristicsAVNetskope IPS

NanoCore is a remote access trojan written for the .NET framework that gives operators extensive control over infected systems, including remote desktop, file management, keystroke capture, and password recovery. Its source code and builder leaked years ago, and the resulting flood of cracked and modified versions made it one of the most widely abused RAT families. It typically arrives through phishing emails and loader chains, and its plugin architecture lets operators add surveillance capabilities on demand.

First seen
January 2022
Last seen
October 2026
Nanocore

13 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

  • T1027Obfuscated Files or Information

TA0007 Discovery

  • T1016System Network Configuration Discovery

TA0009 Collection

TA0011 Command and Control

TA0112 Defense Impairment

  • T1112Modify Registry
  • T1685Disable or Modify Tools
  • T1686Disable or Modify System Firewall
Alert Name
AIT:Trojan.NanoCore.104
AIT:Trojan.NanoCore.247
AIT:Trojan.NanoCore.297
AIT:Trojan.NanoCore.313
AIT:Trojan.NanoCore.39
AIT:Trojan.NanoCore.58
AIT:Trojan.NanoCore.78
Backdoor.MSIL.Agent.NanoCore
ByteCode-MSIL.Backdoor.NanoCore
ByteCode-MSIL.Trojan.Nanocore