RAT
NanoCore
RAT
30 detections found
Also known as: NanoCore RAT, Nancrat
NanoCore is a modular, .NET-based remote access trojan sold on underground forums since 2013, supporting plugins for keylogging, webcam/microphone capture, file management, and credential theft. Its developer, Taylor Huddleston, pleaded guilty in 2017 to U.S. federal charges for building and distributing the tool knowing it would be used to unlawfully access victims' computers, and was later sentenced to 33 months in prison. Despite the prosecution, leaked builder versions kept NanoCore in wide circulation; CISA listed it among the top malware strains observed in 2021.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- NanoCore, Software S0336 — MITRE ATT&CK
- Arkansas Man Pleads Guilty to Developing and Distributing Prolific Malware — U.S. Department of Justice
- 2021 Top Malware Strains (AA22-216A) — CISA