New Distribution of the NanoCore RAT
ID: 738eba05-e06e-5036-8f60-409e03452282
STIX ID: report--738eba05-e06e-5036-8f60-409e03452282
Feed Name: Zscaler Security Research Blog
Threat Score
Zscaler ThreatLabZ provides a technical analysis of the NanoCore RAT: a multi-stage .NET-based malware that uses DES-CBC encryption and steganography (PNG resource) to load a NanoCore binary in memory. The report details distribution vectors (malicious documents, web downloads, spam), capabilities including credential theft, keylogging and remote execution, lists observed C2 domains and IOCs, and notes sandbox detections and monitoring actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
