Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
30
Global rank
37 infographic chevron month
Month rank
28 infographic chevron week
Week rank

NanoCore is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework and it’s available for purchase for just $25 from its “official” website.

Trojan
Type
USA
Origin
1 January, 2013
First seen
17 September, 2026
Last seen

How to analyze Nanocore with ANY.RUN

Type
USA
Origin
1 January, 2013
First seen
17 September, 2026
Last seen

IOCs

IP addresses
88.221.169.205
184.31.95.119
92.223.97.79
52.110.17.61
34.54.185.247
2.16.238.156
199.232.214.172
52.123.243.75
23.11.41.157
52.110.17.205
57.153.246.3
52.123.243.220
57.155.101.212
199.232.210.172
52.110.17.44
23.194.190.224
52.110.17.208
104.102.63.189
172.255.253.140
8.8.8.8
Hashes
5e9a7996fe94d7be10595d7133748760bf8348198b71b7a50fd8affaa980ac61
b93767833f348c5efc10bd9cd6df6975ccf93eeca107c60614b248bb80f49ae0
4412319ef944ebcca9581cbacb1d4e1dc614c348d1dfc5d2faaaad863d300209
2373b520c5d9dda7e8c2218ff73fca42495e5db960874b54bec2cda4bfefaa23
c9dbf8c73b5432300340e9b9f5459361e8e911384a18d0e4d828cd19d7ba9638
c935b13cb313028b19572ad742c004d7194df1c29125863655a6de6d6ed666ad
2b3d5debf45b11ac8fb7f68525f4fa7fdcded78a0a984d23e9d377986bf6898f
7cf8d385e7141b5bc8c2c48cf20a57c41dfc05d2474ba29c93189a4e193522d8
1907f833a2976565676c9a146b85bf07efa2abf4d5848fa3a644939b1ce16652
a3ff59de94f25602e9d07b57562fb426ad376a2eb7e7beb2f895d117a6ec6c42
af148930e11c5fe0977ea39abc7a83b57db9184838852f7efd041ff108630bcc
f9e66861d9c12f23f5c8ff1ccc3eb45260b84754de7d18c2e5f8aa0a900352cc
03128d7921d884b526f7d3fc7daf1e3a33c3032e727c3a26e032ee074ab26470
7154d40d27e84c6637c01873c81340d733fb5ffaf394bcca003fe796ae9cf62b
6c3cb9cbf9818c8964ca614e54abe0343d5d670e04a26d248836c465001f2432
8b91aef7e782a3c11154834edafdda5433f9be7952ddf74bd8c04bc20a0418ae
46cd360467356ec21c703e7f22e72abf9085a8e2203758306fef00bdc7ee5cd7
dd8bc5cfda83ff9d734ed9fe8eceddc637e4af9ebb4f1b19be873a1ed070c151
fa8c1937230f0ed846dde09aa38dceeb19fa1934dd03986ca31d4c5204f13e4e
b4d5d574fe830f779ba5b687ba7042b1d69cced7ba97dd17e27d3863178a7a7f
Domains
ctldl.windowsupdate.com
google.com
eip-terr-eu.cdp1.digicert.com.akahost.net
fs.microsoft.com
go.microsoft.com
ocsp.digicert.com
incoming.telemetry.mozilla.org
mrodevicemgr.officeapps.live.com
prod.ingestion-edge.prod.dataservices.mozgcp.net
dns.msftncsi.com
ecs.office.com
settings-win.data.microsoft.com
officeclient.microsoft.com
activation-v2.sls.microsoft.com
nexusrules.officeapps.live.com
fe3cr.delivery.mp.microsoft.com
login.live.com
slscr.update.microsoft.com
crl.microsoft.com
www.microsoft.com
URLs
http://www.msftconnecttest.com/connecttest.txt
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6317c24a77a23c81
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://ocsp.digicert.com/
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbsnxliz3fu1wb6n1%2fe6xwn1b0jxiqqudiwawgbh3zfez70pn6odhb7tzrccealxhnr4eln54rgipwq89vq%3d
http://go.microsoft.com/fwlink/?linkid=252669&clcid=0x409
https://mrodevicemgr.officeapps.live.com/mrodevicemgrsvc/api/v1/c2rtargetaudiencedata?omid=97560490bafb0d49bca6f8f0df91025d&susid=c408ee57-2103-4c34-9e6f-30bdf6c87e50&audienceffn=492350f6-3a01-4f97-b9c0-c7c6ddf67d60&tid=&osver=client%7c10.0.22000&offver=16.0.16626.20134&ring=production&aud=production&ch=cc&osarch=x64&manstate=6
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?cd74335b66c748e9
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?d718c1b0da1321c9
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?7fc9d86e771802f4
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?77ea489f2b8524a2
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?82c4813a07aa3cb2
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7ec04170f29af632
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?1975d963832bb946
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?b6921be643b60356
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ca01897af9e5242b
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?9db1387e18e3b787
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?a13881ae8e066ef7
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 681
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 946
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 2552
comments 0

What is NanoCore malware?

NanoCore is a Remote Access Trojan or RAT. This malware is highly customizable with plugins that allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework and it’s available for purchase for just $25 from its “official” website.

This malware was recorded in the wild for the first time in 2013. Since then it has become extremely popular. It is now used in attacks all around the world. As a modular malware, the functionality of the NanoCore backdoor can be greatly expanded with plugins. This makes an already dangerous RAT potentially even more destructive for the company's cybersecurity.

Distributed on its own website with 24/7 technical support for just $25 with all official plugins included, the malware can also be downloaded from hacking forums where its "cracked" version has been leaked multiple times, making it an extremely accessible trojan to set up and use. Unfortunately, the accessibility, ease of use, and a bunch of information on NanoCore are still contributing to its growing popularity. It’s not completely certain whether the malware was being developed as a commercial program for institutions, or the creator had a goal to create malicious software from the beginning, Regardless, NanoCore author, Taylor Huddleston was tracked down and arrested by the FBI.

General Information about NanoCore RAT

According to the analysis, NanoCore’s first beta appeared in 2013. The latest version of the malware is being openly sold on its own website NANOCORE_dot_io. Unfortunately, this helped ensure the high popularity of the malware. Today NanoCore RAT targets victims worldwide. However, the majority of attacks are taking place in the US.

One of the key characteristics of this RAT is that technically savvy attackers are able to greatly expand the functionality of the malware, fine-tuning it to suit their needs, for instance, by adding screen locker functionality to the virus. Some essential plugins are already provided with the purchase bundle on the “official” website. Other even more sophisticated ones are being developed by the community of cybercriminals, that has formed around NanoCore.

For crooks that don’t want to engage in fiddling with plugins, NanoCore provides a straightforward user interface It allows even novice criminals to launch potentially destructive malicious campaigns. Thus further contributing to the popularity of the malware.

Interactive analysis of NanoCore

A video of the execution process provided by ANY.RUN malware hunting service allows us to perform the analysis of the lifecycle of the trojan or other malware such as WSHRAT or Vidar. We can watch NanoCore behavior as well as all processes as they unfold in a secure online environment.

nanocore execution process graph

Figure 1: A visual graph of NanoCore execution processes generated by ANY.RUN

How does NanoCore spread?

NanoCore RAT is distributed using multiple methods. However, the most commonly used is spam email campaigns. They trick users into downloading malicious documents, often presented as price lists or purchase orders.

The emails sometimes contain malicious attachments with .img or .iso extension. The large size of these files makes it difficult to scan them. Some versions of malware are also spread by a ZIP file which evades secure email gateways. Several file structure works here: one file script will download the payload while the rest are decoys that ensure the malicious content goes unnoticed by the system's security.

PowerPoint files acquire the same scenario as the infection chain takes place over multiple stages before the final payload is executed.

NanoCore RAT execution process

NanoCore is delivered to the victim’s PC using the AutoIt program. Not unlike Agent Tesla malware, which is somewhat typical for this type of RATs. Typically, NanoCore is spread using Microsoft Word documents. Infected files contain an embedded executable file or an exploit.

According to the RAT analysis, once the script file is opened an embedded macros download an executable script file and rename it. The downloaded executable file runs itself and creates a child process. The malware is able to use Regsvcs and Regasm to proxy the code execution through a trusted Windows utility.

nanocore execution process tree

Figure 2: A process tree of NanoCore execution processes generated by ANY.RUN

How to detect NanoCore malware using ANY.RUN?

You can identify whether you are dealing with a sample of NanoCore RAT or not by a quick analysis of the files and scripts created by the malware. Most often NanoCore injects into three processes RegSvcs.exe, RegAsm.exe, and MSBuild.exe.

Open "Advanced details of process" for these processes and look at the "Modified files" tab in the "Events" section. If a file named "run.dat" was created by one of these processes and placed in the %Root%:\Users\username\AppData\Roaming[GUID] folder, you can be sure that the malware you are observing is, in fact, NanoCore trojan.

file created by nanocore Figure 3: File created by Nanocore

Conclusion

Thanks to accessibility, ease of use, customization, and plenty of information, the popularity of NanoCore escalated making it one of the most widespread RATs in the world. Even though NanoCores’ creator has been arrested by officials, due to the appearance of several cracked versions, NanoCore is still openly available on hacker forums.

Often, it can be acquired for free, allowing anybody to set up attacks. The popularity of the malware is further aided by the fact that one does not need much programming knowledge to use this Trojan, as it comes equipped with a user-friendly interface. At the same time, very sophisticated and destructive attacks can be carried out with NanoCore RAT by skillful hackers, since its malicious capabilities can be extended with custom plugins. Thankfully, modern analysis tools such as ANY.RUN allow researchers to examine malware in detail, learn about its behavior patterns and set up an appropriate cybersecurity response.

HAVE A LOOK AT

 screenshot
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
Chaos Ransomware screenshot
Chaos ransomware is a malware family known for its destructive capabilities and diverse variants. It first appeared in 2021 as a ransomware builder and later acted as a wiper. Unlike most ransomware strains that encrypt data to extort payment, early Chaos variants permanently corrupted files, while later versions adopted more conventional encryption techniques.
Read More
Grandoreiro screenshot
Grandoreiro
grandoreiro
Grandoreiro is a Latin American banking trojan first observed in 2016. It targets mostly Spanish-speaking countries, such as Brazil, Spain, Mexico and Peru. This malware is operated as a Malware-as-a-Service (MaaS), which makes it easily accessible for cybercriminals. Besides, it uses advanced techniques to evade detection.
Read More
Razr screenshot
Razr
razr
Razr is a destructive ransomware that infiltrates systems to encrypt files, rendering them inaccessible to users. It appends the ".razr" extension to the encrypted files and drops a ransom note, typically named "README.txt," instructing victims on how to pay the ransom to obtain the decryption key. The malware often spreads through phishing emails with malicious attachments or by exploiting vulnerabilities in software and operating systems. Razr employs strong encryption algorithms, making it challenging to decrypt files without the attackers' key.
Read More
DEVMAN screenshot
DEVMAN
devman
DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.
Read More
AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More