NanoCore samples seen in MalwareBazaar

Report date September 11, 2026

NanoCore gives attackers remote access and can steal passwords and emails. It can also activate a webcam.

Background

CISA and ACSC's 2022 overview documents malicious email archives and cloud-hosted documents used in delivery. The listing below does not establish which route a particular file used.

What to do

If your antivirus reports NanoCore, open its detection history to see whether the threat was blocked, quarantined or still needs action. If you use Microsoft Defender on Windows, open Windows Security > Virus & threat protection > Protection history. If the status is Threat found - action needed, follow Defender's recommended action. Threat blocked means Defender reports it removed that threat. Keep a quarantined file quarantined; do not choose Allow on device.

If NanoCore ran, stop using that device for passwords or banking and contact IT on a work device. On a personal Windows device, run a full antivirus scan and follow its removal instructions. From a clean device, change passwords stored or entered on the infected device. Removing malware does not undo stolen credentials. Follow the affected service's account recovery steps.

Feed records

MalwareBazaar listed 1 file sample tagged NanoCore among the 100 uploads checked for this report. This is a count of feed entries, not infected devices. The background above was checked on 2026-09-08; the feed records have their own observation dates.