[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/nanocorerat-behind-an-increase-in-tax-themed-phishing-e-mails/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/nanocorerat-behind-an-increase-in-tax-themed-phishing-e-mails/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# NanoCoreRAT Behind an Increase in Tax-Themed Phishing E-mails

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 6 min read  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Anthony Kasza](https://unit42.paloaltonetworks.com/author/anthony-kasza/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:February 9, 2016

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Microsoft Word](https://unit42.paloaltonetworks.com/tag/microsoft-word/)
  * [NanoCore](https://unit42.paloaltonetworks.com/tag/nanocore/)
  * [NanoCoreRAT](https://unit42.paloaltonetworks.com/tag/nanocorerat/)
  * [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/)
  * [Python](https://unit42.paloaltonetworks.com/tag/python/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/nanocorerat-behind-an-increase-in-tax-themed-phishing-e-mails/?pdf=download&lg=en&_wpnonce=c159619a8e "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/nanocorerat-behind-an-increase-in-tax-themed-phishing-e-mails/?pdf=print&lg=en&_wpnonce=c159619a8e "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=NanoCoreRAT%20Behind%20an%20Increase%20in%20Tax-Themed%20Phishing%20E-mails&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fnanocorerat-behind-an-increase-in-tax-themed-phishing-e-mails%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnanocorerat-behind-an-increase-in-tax-themed-phishing-e-mails%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnanocorerat-behind-an-increase-in-tax-themed-phishing-e-mails%2F&title=NanoCoreRAT%20Behind%20an%20Increase%20in%20Tax-Themed%20Phishing%20E-mails "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnanocorerat-behind-an-increase-in-tax-themed-phishing-e-mails%2F&text=NanoCoreRAT%20Behind%20an%20Increase%20in%20Tax-Themed%20Phishing%20E-mails "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnanocorerat-behind-an-increase-in-tax-themed-phishing-e-mails%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=NanoCoreRAT%20Behind%20an%20Increase%20in%20Tax-Themed%20Phishing%20E-mails%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fnanocorerat-behind-an-increase-in-tax-themed-phishing-e-mails%2F "Share in Mastodon")
  It seems every mainstream news event or holiday has an accompanying phishing campaign. Opportunistic actors hoping to capitalize on the public's attention are often seen sending phishing e-mails with themes related to the news or the season..

It happened this [last holiday season](https://blog.paloaltonetworks.com/2016/01/as-usual-attackers-were-busy-over-the-holiday-season) and will likely continue to occur as long as email is around.

Unsurprisingly, as we near the U.S. deadline for filing our income taxes, Palo Alto Networks researchers have seen an increase in phishing emails specifically related to taxes. This blog details some recent trends we have been able to identify. Palo Alto Networks noticed both executable attachments and Microsoft Word documents with macros designed to download and execute files.

### Tax-Themed Phishing

Looking through recent email attachments determined to be malicious by WildFire, we noticed a trend in subject lines involving tax forms using the keywords 'report', 'tax', 'secure' and 'pin'. Pivoting from subject lines to the hash values and filenames of attachments included in the emails allowed us to expand our initial sample set. Finally, using the [AutoFocus](https://www.paloaltonetworks.com/products/platforms/subscriptions/autofocus.html) API and a bit of Python we were able to collect data about the samples included in the tax-themed phishing and build a data frame for further analysis.

Within the final sample set, we were able to identify 70 unique malware samples distributed through 2,062 email sessions between September 2, 2015 and January 28, 2016. As expected, email sender addresses were often spoofed to provide a sense of legitimacy.

Some examples of email sender addresses:

* 2015-autax-return@ato.gov.au
* 2015Refund@cra-arc.gc.ca
* 2015autaxreturn@ato.gov.au
* 2015tax-return@irs.gov
* 2015taxreturn-noreply@irs.gov
* 2015taxreturn@iras.gov.sg

We also noticed the source IP address of the emails primarily came from a free mail service called mail2world. The top 5 source IP addresses by session count were:

* 209\.67.128.221 934 sessions
* 117\.120.5.194 214 sessions
* 209\.67.128.182 213 sessions
* 23\.235.221.158 63 sessions
* 130\.194.13.86 53 sessions

While some of the phishing email attachments were PE files, others were MS Word documents with malicious macros. One sample (119f3dd48e316f77974a7ec84c0fdecd943ceed77c30db9a6df0c1b0615b0ac0) included instructions on how to enable macros.

[![ENABLE\_MACROS](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/ENABLE_MACROS-500x433.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/ENABLE_MACROS.png)

Using open source tools, the obfuscated file download functionality is easily located in the Word macro.

[![tax1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/tax1-500x239.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/tax1.png)

Looking at the malware contained in each email attachment, the payloads consisted predominantly of NanoCoreRAT or a generic macro downloader that would then download and execute NanoCoreRAT. The countries receiving these phishing messages align with what are believed to be country code indicators in malicious URLs and email attachment names.

[![tax2](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/tax2-500x296.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/tax2.png)

Recipients of Tax-Based Phishing E-mails

Analyzing the malicious macro documents we observed for these tax-themed phishing attacks revealed that although there were a large number of unique samples, their behavior and infrastructure contained significant overlap.

[![tax3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/tax3-500x280.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/tax3.png)

In the above figure, we can easily see that six domains were in heavy use by most samples.

Second-stage download:

* www.cnw-inc\[.\]com
* www.iphonetechie\[.\]com

NanoCoreRAT Command and Control:

* dawood01.ddns\[.\]net
* dawood02.no-ip\[.\]org
* dawood00.no-ip\[.\]org

### NanoCore

NanoCore is a commodity trojan developed in the .NET framework. According to [Symantec](https://www.symantec.com/connect/blogs/nanocore-another-rat-tries-make-it-out-gutter), a fully cracked version of NanoCore 1.2.2.0 with premium plugins was released around March 2015 and has been seen targeting the energy sector. This release caused NanoCore to become increasingly popular with adversaries, especially the more frugal ones. Around April 2015 we observed a rise in activity involving NanoCore. We have observed its incorporation into tax-themed phishing since June 2015 and are continuing to see a general increase in activity since then. Below shows the upward trend Palo Alto Networks has seen in NanoCoreRAT being distributed since September 2014.

[![tax4](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/tax4-500x181.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/tax4.png)

NanoCore is a modular RAT with many of its capabilities provided through plugins. Capabilities provided by the premium plugins we could identify include:

* keylogging and password "recovery"
* "stress testing" or DoS
* download, execute, or install other software
* remote CLI and UI
* registry editing
* socks proxy
* firewall modification
* webcam and audio controls

The plugins available to a NanoCoreRAT sample are encrypted and stored in the resource section of the PE file.

![tax5](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/tax5-500x299.png)

Using dnSpy as a debugger, we extracted the plugins included in sample 758f255abc102d53b7a4e8a8902da57076db9889cb80e81e8f1a344056f00c59 by setting breakpoints on all Assembly.Load calls, running the sample, and manually dumping the raw assembly bytes passed to those functions to disk as DLLs.

[![tax6](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/tax6-500x322.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/tax6.png)

Most of the plugins included in this sample were obfuscated with Eazfuscater.NET 3.3 and easily deobfuscated using de4dot.

[![tax7](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/tax7-500x248.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/tax7.png)

NanoCoreRAT uses a custom TCP protocol to connect to a server specified by the attacker on the port of their choosing. Below is the encrypted traffic sent by one sample to 54.152.254.8 on TCP port 4782:  
00000000 40 00 00 00 52 5a 31 be 44 a9 01 f5 65 18 54 8e @...RZ1. D...e.T. 00000010 75 be e4 66 6a a4 0f e1 d0 4b 4e 6d 27 b6 19 a1 u..fj... .KNm'... 00000020 0b 21 07 b8 1a 57 60 42 0d 54 d8 4e 1b 04 54 6b .!...W\`B .T.N..Tk 00000030 d5 8c 94 a0 76 88 6f 8a 05 88 dc ca 65 62 54 2b ....v.o. ....ebT+ 00000040 fe d4 ab 7c

|-----------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 | 00000000 40 00 00 00 52 5a 31 be 44 a9 01 f5 65 18 54 8e @...RZ1. D...e.T. 00000010 75 be e4 66 6a a4 0f e1 d0 4b 4e 6d 27 b6 19 a1 u..fj... .KNm'... 00000020 0b 21 07 b8 1a 57 60 42 0d 54 d8 4e 1b 04 54 6b .!...W\`B .T.N..Tk 00000030 d5 8c 94 a0 76 88 6f 8a 05 88 dc ca 65 62 54 2b ....v.o. ....ebT+ 00000040 fe d4 ab 7c |

This sample uses DES to encrypt the traffic. It creates DESCryptoServiceProvider with a key from the Assembly Resource Guide Attribute and bytes from the resource section.  
private static bool smethod\_13() { byte\[\] array = Class8.smethod\_16(); if (array != null) { ... Guid guid\_ = Class8.smethod\_18(Assembly.GetExecutingAssembly()); Class8.byte\_2 = Class8.smethod\_19(byte\_, guid\_); Class13.smethod\_0(Class8.byte\_2); ... } private static Guid smethod\_18(Assembly assembly\_1) { Guid result = new Guid(((GuidAttribute)assembly\_1.GetCustomAttributes(typeof(GuidAttribute), false)\[0\]).Value); return result; } private static byte\[\] smethod\_19(byte\[\] byte\_3, Guid guid\_0) { Rfc2898DeriveBytes rfc2898DeriveBytes = new Rfc2898DeriveBytes(guid\_0.ToByteArray(), guid\_0.ToByteArray(), 8); return new RijndaelManaged { IV = rfc2898DeriveBytes.GetBytes(16), Key = rfc2898DeriveBytes.GetBytes(16) }.CreateDecryptor().TransformFinalBlock(byte\_3, 0, byte\_3.Length); }

|-------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 | private static bool smethod\_13() { byte\[\] array = Class8.smethod\_16(); if (array != null) { ... Guid guid\_ = Class8.smethod\_18(Assembly.GetExecutingAssembly()); Class8.byte\_2 = Class8.smethod\_19(byte\_, guid\_); Class13.smethod\_0(Class8.byte\_2); ... } private static Guid smethod\_18(Assembly assembly\_1) { Guid result = new Guid(((GuidAttribute)assembly\_1.GetCustomAttributes(typeof(GuidAttribute), false)\[0\]).Value); return result; } private static byte\[\] smethod\_19(byte\[\] byte\_3, Guid guid\_0) { Rfc2898DeriveBytes rfc2898DeriveBytes = new Rfc2898DeriveBytes(guid\_0.ToByteArray(), guid\_0.ToByteArray(), 8); return new RijndaelManaged { IV = rfc2898DeriveBytes.GetBytes(16), Key = rfc2898DeriveBytes.GetBytes(16) }.CreateDecryptor().TransformFinalBlock(byte\_3, 0, byte\_3.Length); } |

[![tax8](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/tax8-500x679.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/tax8.png)

The DES key for this sample is 72 20 18 78 8C 29 48 97, we can use it to decrypt the traffic into the following:

*00 00 00 00 12 DD DF 82 E7 AE 59 ED 45 B3 F4 E2 B5 7D 53 A5 EE 0C 14 57 49 4E 2D 48 55 46 44 39 33 41 52 36 32 32 5C 6A 6F 68 6E 0C 07 44 65 66 61 75 6C 74 0C 07 31 2E 32 2E 32 2E 30* *.....Ýß‚ç®YíE³ôâµ}S¥î..WIN-HUFD93AR622\\john..Default..1.2.2.0* *System Guid ComputerName\\Username RAT Group Version*

The bytes are stored in array2 and are encrypted with the following code and stored in the byte array named buffer.  
byte\[\] buffer = Class13.icryptoTransform\_0.TransformFinalBlock(array2, 0, array2.Length);

|---|---------------------------------------------------------------------------------------------|
| 1 | byte\[\] buffer = Class13.icryptoTransform\_0.TransformFinalBlock(array2, 0, array2.Length); |

NanoCore can output messages to a console if the EnableDebugMode parameter is enabled in the RATs configuration.

[![tax9](http://blog.paloaltonetworks.com/wp-content/uploads/2016/02/tax9-500x633.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/02/tax9.png)

### Conclusion

Phishing is often how threat attackers gain access to targeted systems and user awareness is the first line of defense. Phishing isn't new but the increased distribution of the full-featured NanoCoreRAT implants is. Users should be made aware of the dangers that enabling macros poses. We have observed macro-based attacks on the rise in October of 2014

Palo Alto Networks customers with WildFire turned on would have been alerted to the presence of this threat on their networks. AutoFocus customers are able to further research both tax-themed phishing and [NanoCoreRAT](https://autofocus.paloaltonetworks.com/#/tag/Unit42.NanoCoreRAT) samples and trends.

### Indicators

#### Email Subject Lines

\[Attention\] Your 2014 Tax Report

\[Urgent Attention\] Your 2015 Secure IP PIN

\[ATO: URGENT\] Your 2014 Tax Return Report!

\[URGENT ATTENTION\] Your 2014 Tax Return!

\[ATO: ATTENTION\] Your 2015 Tax Return PIN!

\[IRS ATTENTION\] Your 2015 Secure IP PIN!!!

\[HMRC ATTENTION\] Your 2015 Tax Report PIN!

\[ATTENTION\] Your 2015 Tax Return PIN!!!

#### Email Attachment Filenames

IRSReport.doc  
CATAXREPORT.doc  
2015TaxPIN.pdf.exe  
\[CRA\]Report.pdf.exe  
SGTAXREPORT.doc  
\[CRA\]TaxReport.doc  
\[IRS\]TaxReport.doc  
\[HMRC\]TaxReport.doc  
TaxReport!!.doc  
SGTAXREPORT.pdf.exe  
\[CRA\]ReadReport.doc  
UKTaxReturnReport.pdf.exe  
CATaxReturnReport.pdf.exe  
\[CA\]Report.pdf.exe  
\[BE\]TaxReport.pdf.exe  
US2015TaxPIN.doc  
AUTaxReport.pdf.exe  
AU2015TaxPIN.doc  
2015TaxPIN.doc  
CRA-Report.doc.exe  
TaxReport.doc  
UKTAXREPORT.doc  
AUTAXREPORT.doc  
CATaxreturn.doc  
\[CRA\]Report!.pdf.exe  
FRTaxReport.pdf.exe

#### Email Attachment SHA256s

b633e5b9d6961f63dbf07ccd864903948a3c0772f2f66f86ad42c5b1faa0c539  
a1bc606d12db420c511ba94f042021d34d84ba98a16c016445632ed03d37f909  
bbbc92b4ebab54a3b7e35168a0e89ecbae701d3a04ea0df9bb5c132fcb8fa2aa  
a89dd66865554cbe2b1ea6ff18653e964ac48ef585458d7f2d18f3083d039b39  
6c1eb38781214b88cc9f9eb702ad9655f32e033ffa493e0954100b6be9c12d98  
4b1b9fa256a6e6473c5ca25ce30ccdb4f955abb5e620d219dce85152d9e440ed  
d910ffe4bb03c3b0066877b75c8ce5f5bc7ad1ae74908d96f7571bb75bf485f3  
a827613e8a9d69f6401a25690e2282722b901b31f748c1ed2766e680bc14e77c  
ba37d89a20a944cdee5cc4bd146cc225124091f9a576b1c5d6fa0239f3628b38  
fc8da8715a9cab9643c63c7dacf83613478b11b2fc758d2b3b989ffbba9b93af  
899e395fd22b8dc909a26c8fb380eac00e51e2b8766ef363d2a1c75335a40591  
c4e0c88aa4c1a3da9a21114b22b546e238643146603ca667ea2158f142149507  
b13305fe5d3c9e904ffe8d39fcc363f4fa799f5c57c854bf5a5e1ce9307942a4  
200b1ed7f776d4ee32430ffdffefc76c44f359c19a7dff90e5b5ecdbef8e5608  
3f1fc0757542fd80f216753d34ec27569f826d690a520d16017cd6f35acb4be8  
fbcb8f3de748be39c396deea1f172213ff203f3997c575b017ed5e6e2c46ba18  
119f3dd48e316f77974a7ec84c0fdecd943ceed77c30db9a6df0c1b0615b0ac0  
71755fd086ccf44e384d59e91234906403aaf28d73fea96ffa052187c2824b6a  
e2c3c2949f12556b5df7ead551eea2e9a0827dafdf385be2d1f470ba768be4f0  
283152ea205f4098e221b6dab94e5c61619d507b4e8ad3613f7df4ffac35ba88  
23067c7dd27eeeab574aa7cf65fd2b287c2ff794aed3589ff89419a71b740afd  
ea97f1c48ed8e91e5e53683417893dc99f620acbd90b20b069e891c8875fa3ee  
11b2db6fe850cbd373b5222e2512603e3bda0be749910e15d2961a373d56dde8  
09a73ceeaf543a7741503c477af939aa59d13ba1d81983844a4b94bdfa27396a  
6d3917640123e89a714cb0f165c91ae3ffcf8b7bb6321c57c96684952982fbef  
4f60ebf97267480ab084e0851759b18111427e63628ba89a0deaea24c987cf3c  
0175575982f1d298b980583cd48d3d7cdc14ce944352fd259a76f46a58bc609b  
371fa8f45c0203d3470db7518571a8ced1070d2836e3d697e02c614d0b6fe401  
a222d3095d93afbbc59f15ef9fce75dcfbd19eb9d619a8536fd8e49935220319  
657758c09948c3203283fe61de51a31af77115e30b1f0e0b0296d40f97a2d615  
d60d17f39de0d9298eb629d68276198793a16780260340fb8a2af35087a0ffa1  
323cde2a163b8296159637c536c349756fccc2cf356fa084eb42dc5756627a4a  
572b7dd0a742c5efda10b6ae40e764eb81db1add5736d14dd6dd9e091c711475  
48912c24f24ea296ca00be255a9c8a27b8dd3c7b2755c0a562018e0f04ca5fc1  
e18ba8f98204e754e66d3ab5b5bddef80d0a8e924cf29342ec746570d113d0ce  
f10a42a4f135adf7e71b9f23454bf57d616cb5373135b7a70334f1a8921b12a2  
fa4f12d6aa94d6196b68e304e31d7365c2ebeff465f87012c233d366f08abfed  
326ba05909dc6244e00253ef610aea8904b935c617802d492d889363e3f27fa7  
82c9b0b1076fb2709711142a62d04601896606bdb1647ae1a4e51d2158475138  
6e21a9823b5b7ee7c6a2a7d2323afbd9693cd141cf9d1f80f2030b16a0df0937  
5071acb947d01fc7298df97480a5701bfd1c15e629c7ddfe70c75fd8b3bc9b31  
ca06f69759d2e331a1355af447daa857a5ca5bd8e7dd3d25d5c11f58c4a3cd0e  
40ee213a2b2b26c5c48501e159dc30151d2a31056f4c9a32e256c397bf875b85  
822445be43d5e383971ed3b9a63a9f4c17d0e8d067986cecd14e537f71a0e4f0  
798e0e897035d4b821364435e6eaf620181b8096df65d73aea85ef84d7fd5c2c  
80771e4e8155602b5e40aded581f1e141355942a5c8236ddbfcd9983ec8e4bfd  
b5240a38cab5eea7610e902ac7e62b41c255d82eaaad7cfb39cd49029bf50804  
8d6146bc12d170162ff2b542cf56b07aa91c970416b38ef274a95cd4ecb10063  
6e15e471b76fea17cae4aea600a61680d53a8f857489bc818a7b88092bfdb724  
96ffab6bc9b0d9f2d2e0388aea2c13a263e11c708bca309d5f3b1ffe77a5be5c  
7c7434fc496f7cae0185e4ec40a17b41d24f8a2fdbeae9e64998426a1063e26b  
d1778dd50c2a906bcc8e53372045dd3d976d5071ef8b3817ec28627fc0f4d8df  
83f29a170ffcb9f13e630e1b240cfb0c75ff6854740ccf700e83af40a2dc770b  
677ec33db3d3e9b20894bfc1280d3a9944413434cf4eae844d6f79d49bc372bd  
6a8c5e6026e6a5d4561d4006ae7a3f0ab82d5ba4deb21c904684a6c3a5c75a7c  
3118ca1232a55ee0d718c5efb2590d3af0a19d6a3861f4c7c56ecf0dcc3a8083  
4eca6ea67d389ce85e41804bdb23acd7e34e585b3b92ce521636ffa35d877e32  
fc83728faf8ca614e2798d64ed2eca2691354bf83ff5726d52badcd44787db14  
87971bb9bdaea061ebea3d6903d6df359a13713e0d5aeda0a3fee0df852c3799  
44b6807e0ea21d7f41ca09fa04a8bd1192fd568364a3ac5ba12a7c0de7d57a9d  
455705d79026ddfc758cf069267b6975c677e2a28a0f553baca91a3f95d6dbbc  
37160143a5064b505f050d8d37fbd2d2492c62afa599c9bbe0a6c5f0e20f3300  
d175d0c65acebb61bdefd3e498bb24761c6ffd67c401060649d094e9a7d7753b  
bf1e3483ec56fb480a88c6208f5ba2e51a69361b8cb26b8002f4c3bc562996fb  
73935900282967ad8d1d0822f46c49cd69ae49e15bf63435db5074b6d932ba01  
a34a3e1d0e427c9b112bd647fc5b53f1f8401e12bdcf16d6076dbc17fcaa7537  
b11ac7fcb5d0427b922a8f6ba0bf6078647cb8bf3bed11ca43dc30f0f30157f2  
6335b913b0a900e67155dab585249c1861912116bd53bb46055ee966511f97a8  
cdc350df224011bd95f8fc04cfe355b44f1a3732ea7683339227baaa89a7935e  
161a7c71330f0088b5bc06cc2a80fb1217e1a834d8ca87e749cdafa64f521bc5

#### Email Attachment Resolved Domains

agor0020.gotdns.ch  
btint.net16.net  
dawood00.no-ip.org  
dawood01.ddns.net  
dawood02.no-ip.org  
www.cnw-inc.com  
www.iphonetechie.com  
www.pantech224.firstcom.com.sg  
www.secretchamber.sg

#### NanoCore Deobfuscated Plugin SHA256s

|--------------------------------|------------------------------------------------------------------|
| ClientPlugin.dll               | 277f74d0ce633645c1a3a91b45f800f16385496d50c511084ccbd19c33a39b23 |
| CoreClientPlugin.dll           | 8c18712257e04e0554a4fa8414906489bc4300ee71405719d43ce949decddf18 |
| FileBrowserClient.dll          | 98b70d6b88b8fdf05d8da676fa7a48622c2d415cd5cf8e8a1f193dc6c65dc101 |
| Lzma#.dll                      | ee05e8bd662e8e59c851b4053d2b34e8524cbe5356ee6c385b07d028a9dfb28d |
| ManagementClientPlugin.dll     | 3ad61e99f7a09c524121981f536b625fadcb27481d99ffe75938bb550be8883e |
| MyClientPlugin.dll             | 1e6cc9c0ee28a352611fd1a6b41f4a5e66019729b529d9177b14b25624533cad |
| MyClientPluginNew.dll          | c986b9e146cb4f88dc68bea7927c76e0056e181b7b0de45fe4a221ce5e900d08 |
| NanoCoreBase.dll               | ea8ddf633460353ab0e641b97a370873b16ac4aef3e6ef6bffc2c4618256ab64 |
| NanoCoreStressTester.dll       | edd0e15cdf75f8158c5aae90db3e8c7d7705a247c5d807bc74c027c36ef6dc3d |
| NetworkClientPlugin.dll        | 6995887a9827808ca41ffbfddbeb93b8de9468387ec8958207a3eb9951d286f6 |
| SecurityClientPlugin.dll       | ee5cb353a3e4bdce3ac3b514e2e17e0dd0b04d787b4705c7cf1a681c0b422d85 |
| SurveillanceClientPlugin.dll   | beaf550d664abe4653fd0ddbdd1783894141b51272d8ac565556aa28e2ac847d |
| SurveillanceExClientPlugin.dll | 5db139678bcfda1b46ddab1e2956b599da89a364230d16703a4ac0b02325a13a |
| ToolsClientPlugin.dll          | a4f7a7dddbef1930d11609e4cd7604d1c3a75646db051499b1247b3b03b48692 |
| MyClientPlugin.dll\_2           | 7c1d77c3b41af227c5f6ae49000134420ce9fdd8d3050eceb5aa2358a31a4724 |

#### Additional Resources

* [NanoCore and Unpacking the AutoIT Cryptor](https://www.neutralizethreat.com/2016/01/nanocore-and-unpacking-autoit-cryptor.html)
* [NanoCore: Another RAT tries to make it out of the gutter](https://www.symantec.com/connect/blogs/nanocore-another-rat-tries-make-it-out-gutter)

Back to top

### Tags

* [Microsoft Word](https://unit42.paloaltonetworks.com/tag/microsoft-word/ "Microsoft Word")
* [NanoCore](https://unit42.paloaltonetworks.com/tag/nanocore/ "NanoCore")
* [NanoCoreRAT](https://unit42.paloaltonetworks.com/tag/nanocorerat/ "NanoCoreRAT")
* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")
* [Python](https://unit42.paloaltonetworks.com/tag/python/ "Python")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques](https://unit42.paloaltonetworks.com/t9000-advanced-modular-backdoor-uses-complex-anti-analysis-techniques/ "T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques")

### Related Articles

* [The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "article - table of contents")
* [Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "article - table of contents")
* [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
