Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 21:19:15 UTC Home > List all groups > List all tools > List all groups using tool NanoCore RAT Tool: NanoCore RAT Names NanoCore RAT NanoCore Nancrat Zurten Atros2.CKPN Category Malware Type Backdoor, Info stealer, Credential stealer Description Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras. It has been used for a while by numerous criminal actors as well as by nation state threat actors. Information MITRE ATT&CK Malpedia AlienVault OTX Last change to this tool card: 25 January 2022 Download this tool card in JSON format All groups using tool NanoCore RAT https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=9b69c2d2-7c21-4b16-b039-2400387dd956 Page 1 of 2 Changed Name Country Observed APT groups   Aggah [Unknown] 2018-Jun 2022     APT 33, Elfin, Magnallium 2013-Apr 2024     Gorgon Group 2017-Jul 2020     Group5 2015     Operation Comando [Unknown] 2018     RevengeHotels [Unknown] 2015     TA2722 [Unknown] 2020     Vendetta, TA2719 2020   8 groups listed (8 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=9b69c2d2-7c21-4b16-b039-2400387dd956 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=9b69c2d2-7c21-4b16-b039-2400387dd956 Page 2 of 2