What is the Nanocore RAT?
Nanocore is a .NET remote access trojan that gives an attacker full control of an infected host, including remote desktop, keylogging, screen and webcam capture, and credential theft. Its plugin architecture lets operators extend functionality on demand, and it is typically delivered through phishing attachments as cheap, widely available crimeware.
Why track it with PrecisionSec
- Extensible remote access via plugins. Nanocore’s modular design means one infection can pivot to keylogging, surveillance or theft. Block its C2 before operators load in.
- Cut commodity-malware noise. High-confidence classification lets your SOC filter mass-distributed crimeware and focus on targeted, hands-on threats.
- Built for your stack. Delivered via STIX/TAXII, MISP, CSV and REST API.
Nanocore C2 and distribution IOCs are included in every PrecisionSec intelligence subscription.