Botnet Installing NiceRAT Malware
ID: 5a764330-e476-5563-9e40-aa737d992ff4
STIX ID: report--5a764330-e476-5563-9e40-aa737d992ff4
Feed Name: ASEC
**AhnLab reports that persistent botnets—primarily NanoCore—distributed via cracked software and file-sharing sites have been actively installing additional malware (notably NiceRAT and Nitol) since 2019.** The report documents NiceRAT behavior (anti-analysis, persistence, IP/location collection) and its use of a Discord webhook C2, lists observed C2 domains and URLs, provides file detections and sample MD5s, and warns that these long-lived botnets enable continued secondary malware distribution and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
