logo

Botnet Installing NiceRAT Malware

ID: 5a764330-e476-5563-9e40-aa737d992ff4

STIX ID: report--5a764330-e476-5563-9e40-aa737d992ff4

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-06-13

Date Updated: 2026-04-26

Author: kwonxx

...
...

**AhnLab reports that persistent botnets—primarily NanoCore—distributed via cracked software and file-sharing sites have been actively installing additional malware (notably NiceRAT and Nitol) since 2019.** The report documents NiceRAT behavior (anti-analysis, persistence, IP/location collection) and its use of a Discord webhook C2, lists observed C2 domains and URLs, provides file detections and sample MD5s, and warns that these long-lived botnets enable continued secondary malware distribution and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.