NanoCore RAT Malware
NanoCore is a Windows Remote Access Trojan (RAT) that has been active in the wild since 2013. The RAT provides a wide range of functionality, enabling cybercriminals to do everything from stealing data to controlling the infected computer to mine cryptocurrency.
As a RAT, NanoCore is well-suited for providing initial access, stealing information, and spying on victims. Historically, NanoCore’s remote access and spyware capabilities have been used to attack businesses, stalk victims, and conduct espionage for nation-state groups¹. There are multiple NanoCore plugins which can be purchased (or stolen/cracked) from cyber-crime forums to add new features and capabilities — though NanoCore’s base payload is already capable of:
- accessing files
- executing programs
- stealing saved passwords
- logging keystrokes
- and surveilling webcams