ATT&CKReferencesPaloAlto NanoCore Feb 2016

PaloAlto NanoCore Feb 2016

Kasza, A., Halfpop, T. (2016, February 09). NanoCoreRAT Behind an Increase in Tax-Themed Phishing E-mails. Retrieved November 9, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareNanoCore

NanoCore’s plugins were obfuscated with Eazfuscater.NET 3.3.

T1056.001
Keylogging
MalwareNanoCore

NanoCore can perform keylogging on the victim’s machine.

T1059.003
Windows Command Shell
MalwareNanoCore

NanoCore can open a remote command-line interface and execute commands. NanoCore uses JavaScript files.

T1105
Ingress Tool Transfer
MalwareNanoCore

NanoCore has the capability to download and activate additional modules for execution.

T1112
Modify Registry
MalwareNanoCore

NanoCore has the capability to edit the Registry.

T1123
Audio Capture
MalwareNanoCore

NanoCore can capture audio feeds from the system.

T1125
Video Capture
MalwareNanoCore

NanoCore can access the victim's webcam and capture data.

T1573.001
Symmetric Cryptography
MalwareNanoCore

NanoCore uses DES to encrypt the C2 traffic.

T1685
Disable or Modify Tools
MalwareNanoCore

NanoCore can modify the victim's anti-virus.

T1686
Disable or Modify System Firewall
MalwareNanoCore

NanoCore can modify the victim's firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.