ATT&CKReferencesCofense NanoCore Mar 2018

Cofense NanoCore Mar 2018

Patel, K. (2018, March 02). The NanoCore RAT Has Resurfaced From the Sewers. Retrieved September 25, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareNanoCore

NanoCore can open a remote command-line interface and execute commands. NanoCore uses JavaScript files.

T1059.005
Visual Basic
MalwareNanoCore

NanoCore uses VBS files.

T1547.001
Registry Run Keys / Startup Folder
MalwareNanoCore

NanoCore creates a RunOnce key in the Registry to execute its VBS scripts each time the user logs on to the machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.