Cybaze-Yoroi ZLab analyzed a new sample of Nanocore Remote Administrator Tools (RAT) using a Delphi wrapper to protect its code. CSDC monitoring operations spotted a particular sample of the famous Nanocores RAT. The interesting thing is the payload, that is further loaded into memory, is merely embedded into a resource without any encryption or obfuscation. This action is performed through the usage of the classical Win32 API calls CreateToolhelp32Snapshot and Process32Next”]
Source: https://securityaffairs.co/wordpress/87103/malware/dissecting-nanocore-crimeware.html