typeentityconfidencehighcreated2026-06-02updated2026-09-06malware-familyratdotnetc2persistenceobfuscation

NanoCore

Overview

NanoCore is a commodity .NET-based remote-access trojan (RAT) whose builder leaked around 2014–2015. It remains actively distributed via spam, cracked software bundles, and phishing lures. The client is highly configurable through a point-and-click builder that generates a small (~150–300 KB) obfuscated EXE targeting .NET Framework 2.0–4.x.

Build-Stack Typically Observed

  • Language: C# or VB.NET (Visual Studio / SharpDevelop).
  • Framework: .NET Framework 2.0 (CLR v2.0.50727) or .NET 4.x.
  • Builder: NanoCore Builder (version stamps like 1.2.2.0 seen in leaked-era builds).
  • Obfuscator: Frequently confuserex-obfuscation — mass name mangling (#=q…==), resource encryption, control-flow flattening. Also observed with Eazfuscator, Dotfuscator, and SmartAssembly.
  • Package: Single PE32 with 3 sections (.text, .reloc, .rsrc). .rsrc often contains an encrypted ZIP or manifest payload.
  • Signing: Usually unsigned; Authenticode stripped. ^[sample fe81691f/pefile.txt]

Deploy / TTPs Typically Observed

  • Persistence: Registry Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) or copied to %AppData% / %TEMP%. ^[sample fe81691f/capa.txt:95-99]
  • C2 Protocol: Raw TCP sockets (not HTTP/HTTPS). Builder-configured host/port list; client caches entries and supports server-driven host updates via AddHostEntry / RebuildHostCache. Keepalive framing. ^[sample fe81691f/capa.txt:62-66]
  • Plugin Architecture: Modular design — IClientApp, IClientNetwork, IClientUIHost, etc. Plugins loaded reflectively from encrypted resource packages. IPC via named/anonymous pipes. ^[sample fe81691f/strings.txt:86-97]
  • File System: Creates directories, copies itself, deletes files, writes temp files. ^[sample fe81691f/capa.txt:73-84]
  • Discovery: System information, user name, OS version, hostname, file/directory enumeration, registry queries. ^[sample fe81691f/capa.txt:15-22]
  • Defense Evasion: Heavily obfuscated with ConfuserEx; reflective code loading of plugins; minimal static IAT (only mscoree.dll._CorExeMain). ^[sample fe81691f/pefile.txt:199]
  • MD5 Hashing: Observed in network packet integrity / config checks. ^[sample fe81691f/capa.txt:66]

Variants / Aliases

  • NanoCore RAT — the umbrella label.
  • NanoCore Client — the builder-generated payload EXE.
  • NanoCore Plugin — individual modules (file manager, remote desktop, keylogger, etc.) delivered as encrypted plugin packages.
  • Builder versions: 1.1.x, 1.2.x (leaked era), plus later forks sold in underground markets.

Notable Analyses

  • fe81691f — VB.NET ConfuserEx obfuscated client v1.2.2.0, raw static deep-dive. ^[/intel/analyses/fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5.html]

  • 48c8e8a2 — ConfuserEx sibling build (same timestamp, same builder version, different GUID and encrypted resource). Confirms batch-build behaviour. ^[/intel/analyses/48c8e8a2f28318ae10000d4997784cd12703e182bd50db5da32b930034a0bc4c.html]

  • d065ebea — Third sibling (hotro.exe) in the same Feb 2015 batch, Vietnamese-language filename masquerade. ^[/intel/analyses/d065ebea634c65f1bc3e1b770d09f0364b87a74a631deca80f84f20561533898.html]

  • 4121d69c — Fourth sibling (Backdoor.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client with identical builder version 1.2.2.0. Confirms mass builder-era distribution. ^[/intel/analyses/4121d69c165b16754eb62f1b87930e7c66a69e4c4a5e6526c10e1c4fea547b2f.html] |- 0eedf3a8 — Fifth sibling (Backdoor.exe), same Feb 2015 batch, identical builder version 1.2.2.0, unique GUID ee24ebfc-5674-4134-8aa8-c2651cc2f5d4. Blunt-filename lure; no social-engineering rename. ^[/intel/analyses/0eedf3a80df9b816949c1ac066553d40b5bb0113edec7dedd1b19ab7228ec5a3.html] |- cb2aa275 — Sixth sibling (moocow.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated .NET Framework 2.0 client with internal name NanoCore Client.exe. Full plugin-host interface surface (IClientApp, IClientNetwork, etc.). 88 KB encrypted RCData resource, no hardcoded C2 recovered. Static-only (CAPE skipped). ^[/intel/analyses/cb2aa2757374dcf03c6dec4079e6b4f6eaf68fdd61731e7e922eba679ee6fe07.html] |- e48f1c56 — Seventh confirmed sibling (Backdoor.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. Confirmed twin of fe81691f — only delta is the MyTemplate GUID (f14daca4-… vs b4de0bbe-…) and encrypted .rsrc payload hashes. Blunt filename; no social-engineering masquerade. Static-only (CAPE skipped). ^[/intel/analyses/e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556.html] |- 12deaec6 — Eighth confirmed sibling (new88.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. Unique MyTemplate GUID 2601925a-2b07-4fb7-aeb0-80126437ed67. Blunt filename; no social-engineering masquerade. Static-only (CAPE skipped). ^[/intel/analyses/12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287ac.html] |- b6008cf6 — Ninth confirmed sibling (mmdx2.ru.com.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Unique MyTemplate GUID 630148c0-c72e-4620-938d-13f9c119d87b. Russian domain masquerade filename; ~90 KB encrypted RCData in .rsrc. Static-only (CAPE skipped). ^[/intel/analyses/b6008cf64e5ec8d7756cd1fc8e0e76b7e420529d41e83b66022b76ebb26b1eeb.html] ||- f017a517 — Tenth confirmed sibling (EMU.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. Emulator/game-utility social-engineering masquerade; 89,960-byte encrypted RCData in .rsrc. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/f017a517cca5e63ad557dc9541ab6284a23ecfb7e6ccbc0d24bf42981af81d6f.html]

  • 37509ef2 — Eleventh confirmed sibling (Nemo.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. Disney/Finding Nemo social-engineering masquerade; 88,928-byte encrypted RCData in .rsrc. Unique GUID 6d10e433-cda2-420f-9bab-c964ccf1d3ca. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/37509ef29401d29e69288a7975f57e3787c5cb4122b95ae159078a396037f242.html] |||- 112d957b — Twelfth confirmed sibling (gwwsite.nl.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch domain masquerade; 90,464-byte encrypted RCData in .rsrc. Unique GUID ead3cb61-5c13-4ced-8ae6-88a547e425c9. RijndaelManaged + DeflateStream decryption pipeline confirmed in strings. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/112d957b56a0ccec1e06defc317c8b7b169b6e74514d1a6f7bee8c2b32b080ae.html] |- 96ddc5067 — Nineteenth confirmed sibling (cash-win.nl.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch domain masquerade (cash-win.nl); 89,952-byte encrypted RCData in .rsrc. Unique GUID 21b9771a-0ead-4a20-9584-91c88cd03202. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910.html]

|- b5bbf49b — Twentieth confirmed sibling (nega.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Bare filename with no social-engineering masquerade; 88,152-byte encrypted RCData in .rsrc. Unique GUID cce15acd-4387-46c9-8e17-643151fbfa1d. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499.html]

Capabilities

  • registry-run-persistence
  • dotnet-reflective-assembly-loading
  • raw-tcp-c2-keepalive
  • host-cache-dynamic-update
  • pipe-based-plugin-ipc
  • confuserex-name-obfuscation
  • resource-zip-encryption
  • file-system-copy-delete
  • registry-query-enumeration
  • system-information-discovery
  • md5-hash-data-check
  • rijndael-deflate-resource-decryption

Related Entities / Techniques

  • confuserex-obfuscation — primary obfuscator observed.

  • smartassembly-obfuscation — alternative commercial .NET obfuscator seen with other families.

  • 930b692d — Fourteenth confirmed sibling (jvegter.nl.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch domain masquerade (jvegter.nl); 90,464-byte encrypted RCData in .rsrc. Unique GUID 08186e7b-fc6a-4a22-832f-d29dc50a34fc. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/930b692df3835501f7c276763fbf80928fe64d808e8f1f52d8fe091a5e58ca56.html]

  • 36115e96 — Fifteenth confirmed sibling (coffeeandsuch.nl.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch domain masquerade (coffeeandsuch.nl); 90,608-byte encrypted RCData in .rsrc. Unique GUID 8dc51bf4-8f2c-404b-98a0-1d777ffdbc54. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/36115e96dd16090fa669229c36d861ac7cff249e5562a3a272e74db1b7da33e7.html]

  • e4774281 — Sixteenth confirmed sibling (aboddehousing.co.uk.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. UK housing-domain masquerade (aboddehousing.co.uk); ~90,464-byte encrypted RCData in .rsrc. Unique GUID 15e065f2-6a0c-418b-8192-dc66272ecfda. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1.html]

|- 38cac999 — Seventeenth confirmed sibling (nam.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Bare filename with no social-engineering masquerade; ~90,464-byte encrypted RCData in .rsrc. Unique GUID 47a89a76-c40c-4e5f-9273-94732e5f42cf. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/38cac999881944e48e997877535b8cc653bc2b441e8e7e8eaa5773207848df72.html]

||- b0daeb6a — Eighteenth confirmed sibling (schoenberg-ensemble.nl.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch classical-music domain masquerade; ~90,080-byte encrypted RCData in .rsrc. Unique GUID 7e3c957d-3516-4313-add2-1d2b57e0ca5f. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11.html]

||- 4eed8d8f — Twenty-first confirmed sibling (sh4.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Bare three-character filename with no social-engineering masquerade; 90,176-byte encrypted RCData in .rsrc. Unique GUID a96b9d76-0029-412c-98b8-5276d49306fe. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/4eed8d8f0ee2f147dd5106c5d783085a3964b127f88f8e4a203896c40fb88e28.html]

|- 96ddc5067 — Nineteenth confirmed sibling (cash-win.nl.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch domain masquerade (cash-win.nl); 89,952-byte encrypted RCData in .rsrc. Unique GUID 21b9771a-0ead-4a20-9584-91c88cd03202. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910.html]