Nanocore malware family
Nanocore is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-08-04, most recently 2026-08-22. Observed ATT&CK techniques include T1112, T1543.003.
Corpus statistics
- Publicly analyzed samples: 9
- First seen: 2026-08-04
- Last seen: 2026-08-22
- Verdicts: malicious 9
- File types: pe 9
ATT&CK techniques used by Nanocore
Extracted command-and-control infrastructure
- 1.2.2.0 - 1 sample
Recent Nanocore samples
- 1bb4a67358104a600546e9061b77d4218d486354629d7473d8c06b3de556c89e - malicious (2026-08-22)
- a5228e0087e7459608c1548b8e82328008fb37a5638b4317965520bdd37b918a.exe - malicious (2026-08-17)
- c14164aa5550fec91514f073f35bbd23c28bc7eb740bc930c1e29daf9a9ed9ce.exe - malicious (2026-08-15)
- 8d423e57b2cf148ce393b09c1c67540f591af26b242ec428b4b7986a17fadf30.exe - malicious (2026-08-14)
- 656a0518875d72b0cce6b288cb71d13cc0b6afc3e45cf9b578b9092a3f7da2bf.exe - malicious (2026-08-13)
- nanocore.exe - malicious (2026-08-13)
- 3ea98de8eb624a2bcab8a309c6f5e1f624243fe8d2397f03d3752c92db67c38e - malicious (2026-08-12)
- d98ed60ba1c3d819f1447cc55a3209783f84322173e749550e4d482febf94f8e - malicious (2026-08-11)
- 0ec1ed0daf72e7f3b2a9afb44d8e2de77b97b126788e54e0cb948cc176de91ba.exe - malicious (2026-08-04)
Frequently asked about Nanocore
- What is Nanocore?
- Nanocore is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-08-04, most recently 2026-08-22. Observed ATT&CK techniques include T1112, T1543.003.
- How many Nanocore samples have been analyzed?
- MalwareAnalyzer by Cyble holds 9 publicly analyzed samples attributed to Nanocore, first seen 2026-08-04 and most recently 2026-08-22. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Nanocore use?
- Across our Nanocore samples the most frequently observed techniques are T1112 (1), T1543.003 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Nanocore use?
- Nanocore samples in this corpus are distributed as pe (9).
- Does Nanocore use command-and-control infrastructure?
- Yes. 1 distinct command-and-control indicator has been extracted from Nanocore samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Nanocore malicious?
- 9 of 9 analyzed Nanocore samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends