Skip to content
Malware family Windows

QuasarRAT

Quasar RAT is an open-source Windows remote access trojan written in .NET/C# and publicly available since 2015.

Profile source: Mallory opens in a new tab

QuasarRAT

Family profile

Quasar RAT is an open-source Windows remote access trojan written in .NET/C# and publicly available since 2015. It has been widely reused in criminal operations, opportunistic malware distribution, and state-linked intrusion sets, making it both a standalone malware family and a building block for derivative tools and customized implants. Security reporting has associated Quasar RAT usage with campaigns involving repository backdoors, phishing-delivered loaders, software supply-chain abuse, and post-compromise tooling in broader intrusions. It has also been used by actors including APT10/menuPass and has influenced or been cloned by later families such as AsyncRAT and VenomRAT; some operations have also deployed Golang reimplementations such as GOSAR.

Quasar RAT provides typical remote administration and surveillance capabilities for Windows victims. Documented functionality includes remote command execution, registry editing, webcam viewing, user and account-type enumeration, hidden-window execution, concealment of web requests from the user, and the ability to set files as hidden for defense evasion. Reporting also places Quasar-family implants in multi-stage chains that use reflective or in-memory loading, AMSI tampering, process injection, and persistence mechanisms such as services or scheduled execution, although some of those behaviors may be implemented by loaders or customized wrappers rather than the core public project itself.

Quasar RAT is commonly delivered as a downstream payload rather than the initial infection vector. Observed delivery chains include phishing and spearphishing lures, malicious archives, trojanized GitHub repositories, fake software projects, deceptive developer packages and extensions, and loader ecosystems that retrieve Quasar alongside stealers, miners, or other RATs. In several campaigns it appeared as one of multiple final payloads, providing redundant remote access after initial compromise.

The malware targets Windows systems and has appeared across a broad victim set, including governments, managed service providers, financial institutions, developers, and users targeted through tax, cryptocurrency, gaming-cheat, and software-development lures. Because Quasar RAT is open source and broadly adopted, its presence alone is not attributionally unique; it is frequently repurposed, modified, and embedded in larger intrusion workflows.

Capabilities

  • Defense Evasion
  • Persistence
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
87 IP / 185 hostnames

Leading locations

  • US129
  • CN35
  • HK26
  • DE11
  • NL5
  • SG5
  • GB4
  • RU3
  • VN3
  • BE1
  • BR1
  • CA1

Leading providers

  • Cloudflare, Inc.122
  • Alibaba (US) Technology Co., Ltd.22
  • Shenzhen Tencent Computer Systems Company Limited17
  • Cloudie Limited4
  • OOO GETWIFI4
  • Amazon.com, Inc.3

Infrastructure traits

  • Hosting 211
  • Anycast 124
  • Proxy 14
  • Vpn 8
  • Mobile 1
  • Residential Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

17 named in public reporting
menuPass

That same reporting identified new or expanded tooling, including HAYMAKER, SNUGRIDE, BUGJUICE, SOGU, and customized QUASARRAT.

Molerats

01/2017: Downeks and Quasar RAT Used in Recent Targeted Attacks Against Governments – Unit42

Patchwork

Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.

SilverTerrier

The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.

APT33

Quasar RAT (Trojan.Quasar): Commodity RAT that can be used to steal passwords and execute commands on an infected computer.

Kimsuky

The attack chain, the company explained, initiated a multi-stage sequence that culminated in the deployment of an open-source remote access trojan named Quasar RAT.

TA429

The blog claims that this URL delivered a modified Quasar RAT payload which included the addition of SharpSploit, an opensource post-exploitation tool.

DarkCasino

QuasarRAT v1.4.1.0 serves as the primary implant -- a full-featured .NET RAT with credential stealing via browser password databases, keylogging through the Gma.System.MouseKeyHook library, registry manipulation, and file management capabilities. A second variant, QuasarRAT v1.8.8 "Sentinel", was discovered packed with Costura and bundled with six DLLs providing HVNC (Hidden Virtual Network Computing), dedicated keylogging, and browser credential theft modules.

Water Hydra

QuasarRAT v1.4.1.0 serves as the primary implant -- a full-featured .NET RAT with credential stealing via browser password databases, keylogging through the Gma.System.MouseKeyHook library, registry manipulation, and file management capabilities. A second variant, QuasarRAT v1.8.8 "Sentinel", was discovered packed with Costura and bundled with six DLLs providing HVNC (Hidden Virtual Network Computing), dedicated keylogging, and browser credential theft modules.

CTG-5938

Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike

APT-C-36

TAG-144 leverages a range of commodity remote access trojans (RATs), including AsyncRAT, REMCOS RAT, DcRAT, njRAT, LimeRAT, QuasarRAT, BitRAT, and a Quasar variant known as BlotchyQuasar.

GALLIUM

"Another type of malware that the attackers attempted to use is Quasar RAT."

UAC-0050

...застосовано... ΡˆΠΊΡ–Π΄Π»ΠΈΠ²ΠΈΡ… ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌ: REMCOS RAT, QUASAR RAT, VENOM RAT, REMOTE UTILITIES Ρ‚Π° LUMMASTEALER.

Red Akodon

...using remote access trojans (RAT) like RemcosRAT, QasarRat, AsyncRAT...; the installation of the RemcosRAT and Quasar Trojans was observed.

aluminum_saratoga

β€œALUMINUM SARATOGA uses many openly available tools for its operations, including… QuasarRat…”

Exploited software

Vulnerabilities linked to QuasarRAT

2 CVEs

MITRE ATT&CK

QuasarRAT in ATT&CK

92 distinct techniques

Techniques

92 techniques
T1027 Obfuscated Files or Information T1059 Command and Scripting Interpreter T1105 Ingress Tool Transfer T1140 Deobfuscate/Decode Files or Information T1102.001 Dead Drop Resolver T1564 Hide Artifacts T1059.001 PowerShell T1204 User Execution T1195 Supply Chain Compromise T1560 Archive Collected Data T1071 Application Layer Protocol T1053 Scheduled Task/Job T1562 Impair Defenses T1113 Screen Capture T1543.003 Windows Service T1548.002 Bypass User Account Control T1620 Reflective Code Loading T1562.001 Disable or Modify Tools T1574.001 DLL T1027.003 Steganography T1566 Phishing T1036 Masquerading T1189 Drive-by Compromise T1055 Process Injection T1059.005 Visual Basic T1219 Remote Access Tools T1566.002 Spearphishing Link T1547.001 Registry Run Keys / Startup Folder T1082 System Information Discovery T1112 Modify Registry T1036.005 Match Legitimate Resource Name or Location T1134.002 Create Process with Token T1057 Process Discovery T1204.002 Malicious File T1033 System Owner/User Discovery T1095 Non-Application Layer Protocol T1106 Native API T1027.007 Dynamic API Resolution T1566.001 Spearphishing Attachment T1573.001 Symmetric Cryptography T1564.001 Hidden Files and Directories T1071.001 Web Protocols T1070.004 File Deletion T1027.002 Software Packing T1078 Valid Accounts T1027.009 Embedded Payloads T1055.002 Portable Executable Injection T1069 Permission Groups Discovery T1016 System Network Configuration Discovery T1564.003 Hidden Window T1125 Video Capture T1553.002 Code Signing T1555 Credentials from Password Stores T1059.003 Windows Command Shell T1041 Exfiltration Over C2 Channel T1021 Remote Services T1588.002 Tool T1053.005 Scheduled Task T1592 Gather Victim Host Information T1497.001 System Checks T1555.003 Credentials from Web Browsers T1657 Financial Theft T1087 Account Discovery T1056.001 Keylogging T1001 Data Obfuscation T1083 File and Directory Discovery T1547 Boot or Logon Autostart Execution T1134.001 Token Impersonation/Theft T1573.002 Asymmetric Cryptography T1614 System Location Discovery T1090.004 Domain Fronting T1567 Exfiltration Over Web Service T1571 Non-Standard Port T1090.003 Multi-hop Proxy T1588.004 Digital Certificates T1552.001 Credentials In Files T1059.007 JavaScript T1553.005 Mark-of-the-Web Bypass T1021.005 VNC T1218.005 Mshta T1012 Query Registry T1027.005 Indicator Removal from Tools T1583.003 Virtual Private Server T1090.001 Internal Proxy T1497 Virtualization/Sandbox Evasion T1046 Network Service Discovery T1090 Proxy T1203 Exploitation for Client Execution T1021.001 Remote Desktop Protocol T1210 Exploitation of Remote Services T1195.001 Compromise Software Dependencies and Development Tools T1190 Exploit Public-Facing Application

Reporting

Research mentioning QuasarRAT

Jul 11
Toms Hardware

Fake Go DNS scanner spread malware through over 200 GitHub repos - 'Operation Muck and Load' has published 700 malicious modules since January | Tom's Hardware

Decoded payload stages map to AsyncRAT, Quasar, and Remcos-style RAT detections alongside infostealer behavior.

Jul 10
Security Affairs

222 GitHub Repositories Linked to Fake Go Package Malware Operation

The downstream payload activity maps to AsyncRAT, Quasar, and Remcos-style remote access tools alongside infostealer-like behavior.

Jul 8
Cyber Security News

Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain

The two final implants are a Gh0st RAT derivative with screen capture abilities connecting over port 6666, and a Quasar or AsyncRAT family .NET implant that patches the Antimalware Scan Interface before loading, connecting over port 6351.

Jul 7
Cyderes

Tax Trap: Fake Indian ITR Notice to Dual RAT Deployment in Six Stages

The in-memory .NET assembly is a Quasar/AsyncRAT-family implant... The decrypted configuration yields the following indicators... C2 Host ouewop[.]com C2 Port 6351 Version Reach 2.0.1 Mutex 5sGEm6Q4eTNv.

Jul 6
The Hacker News

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

a custom malware loader dubbed SADBRIDGE, which is designed to deploy a Golang-based reimplementation of Quasar RAT known as GOSAR.

Jun 30
Cyberveille

AsyncRAT Family : cartographie de 40 variants RAT et leur infrastructure C2 active | CyberVeille

Malware / Outils # ... Quasar RAT (rat) ...

Jun 11
Krypt3ia Wordpress

Threat Intelligence Report: APT10 / FUNKY FLAGPOLE / MenuPass / Stone Panda | Krypt3ia

That same reporting identified new or expanded tooling, including HAYMAKER, SNUGRIDE, BUGJUICE, SOGU, and customized QUASARRAT.

May 21
Cyber Security News

Gremlin Stealer Stores C2 URLs and Exfiltration Paths in Encrypted Resource Sections - Cyber Security News

This technique mirrors tactics used by malware families like Agent Tesla, GuLoader, LokiBot, and Quasar RAT, which rely on the resource section to bury their payloads.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.