logo

New Distribution of the NanoCore RAT

ID: 738eba05-e06e-5036-8f60-409e03452282

STIX ID: report--738eba05-e06e-5036-8f60-409e03452282

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ provides a technical analysis of the NanoCore RAT: a multi-stage .NET-based malware that uses DES-CBC encryption and steganography (PNG resource) to load a NanoCore binary in memory. The report details distribution vectors (malicious documents, web downloads, spam), capabilities including credential theft, keylogging and remote execution, lists observed C2 domains and IOCs, and notes sandbox detections and monitoring actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.