Kasza, A., Halfpop, T. (2016, February 09). NanoCoreRAT Behind an Increase in Tax-Themed Phishing E-mails. Retrieved November 9, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareNanoCore | NanoCore’s plugins were obfuscated with Eazfuscater.NET 3.3. |
| T1056.001 Keylogging |
MalwareNanoCore | NanoCore can perform keylogging on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareNanoCore | NanoCore can open a remote command-line interface and execute commands. NanoCore uses JavaScript files. |
| T1105 Ingress Tool Transfer |
MalwareNanoCore | NanoCore has the capability to download and activate additional modules for execution. |
| T1112 Modify Registry |
MalwareNanoCore | NanoCore has the capability to edit the Registry. |
| T1123 Audio Capture |
MalwareNanoCore | NanoCore can capture audio feeds from the system. |
| T1125 Video Capture |
MalwareNanoCore | NanoCore can access the victim's webcam and capture data. |
| T1573.001 Symmetric Cryptography |
MalwareNanoCore | NanoCore uses DES to encrypt the C2 traffic. |
| T1685 Disable or Modify Tools |
MalwareNanoCore | NanoCore can modify the victim's anti-virus. |
| T1686 Disable or Modify System Firewall |
MalwareNanoCore | NanoCore can modify the victim's firewall. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.