ATT&CKReferencesDigiTrust NanoCore Jan 2017

DigiTrust NanoCore Jan 2017

The DigiTrust Group. (2017, January 01). NanoCore Is Not Your Average RAT. Retrieved November 9, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareNanoCore

NanoCore gathers the IP address from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareNanoCore

NanoCore has the capability to download and activate additional modules for execution.

T1112
Modify Registry
MalwareNanoCore

NanoCore has the capability to edit the Registry.

T1123
Audio Capture
MalwareNanoCore

NanoCore can capture audio feeds from the system.

T1125
Video Capture
MalwareNanoCore

NanoCore can access the victim's webcam and capture data.

T1685
Disable or Modify Tools
MalwareNanoCore

NanoCore can modify the victim's anti-virus.

T1686
Disable or Modify System Firewall
MalwareNanoCore

NanoCore can modify the victim's firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.