Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 157 IP / 200 hostnames
Quasar RAT is a Windows-focused .NET remote-access trojan that provides an operator-controlled command-and-control implant on compromised hosts.
Profile source: Mallory opens in a new tabQuasarRAT
Quasar RAT is a Windows-focused .NET remote-access trojan that provides an operator-controlled command-and-control implant on compromised hosts. It can obtain passwords stored by common web browsers, modify the Windows Registry, and maintain persistence across reboot through scheduled tasks. Quasar RAT has been deployed on compromised IIS servers by the Chinese-speaking financially motivated actor UAT-10147, which used it alongside web shells, BadIIS, Gh0stCringe, and other post-exploitation tooling; observed activity included targeting of internet-facing servers across government, education, media, technology, and gaming organizations. It has also appeared in campaigns associated with Molerats and has communicated with infrastructure linked to Sable Squirrel. Observed delivery chains include phishing-distributed malicious RAR archives exploiting CVE-2025-8088 and social-engineering campaigns using Microsoft OneNote documents containing embedded payloads.
C2 tracking
Derp observations, rolling seven-day window
Samples
7e9e1212464885777e000713ee20d492dea973ac24d5c614ed8a20dab057fe77 fda19deaa898c61e925c5e9866049dff8cdf1fe06caddcacec92c50b37c84e1e 41688db66691792a34f5c607cbc9658c4ef8fa08ae24b95e9c9a611063563cd9 4426c4d0649b28583eefa94451e69ca8a99b3811362fda7ae79a971ffb83b90e 45b448b5f23febfc109fad7a73c55310a6212fd4ff8a8b35ff09ec0a1fffa370 949d829f07ec9325fbe9ff70a169ac47566635a915dc9035c3cd4af0a09481c4 e7068f41fe0b98d551d1409e2f6196303baee0056737086af026cc14bc91ac3d 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 Reported operators
“Its broader toolkit includes BadIIS, QuasarRAT, Gh0stCringe, Noodle RAT, Meterpreter, and multiple members of the Potato privilege escalation family.”
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
Quasar RAT: Hashes (SHA-256 + SHA-1) ... Domains Lynsub[.]com IPs 193.160.32.118
They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe.
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
In 2019, a suspected TA406 operator uploaded several files to VirusTotal (NavRAT, QuasarRAT and BabyShark downloader).
While an ISO file was also used in this attack, the payload is a different Remote Access Trojan, “Quasar RAT”.
Attackers also installed the QuasarRAT open-source backdoor and novel Backdoor.Hartip tool to continue surveillance on victims’ systems.
UAC-0086 (QuasarRAT)
In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.
all of them have been associated with off-the-shelf malware like QuasarRAT, BitRat, and similar.
Quasar is an open source RAT (Remote Administration Tool) with a variety of functions. JPCERT/CC has confirmed that a group called APT10 used this tool in some targeted attacks against Japanese organisations.
Quasar is an open source RAT (Remote Administration Tool) with a variety of functions. JPCERT/CC has confirmed that a group called APT10 used this tool in some targeted attacks against Japanese organisations.
Quasar is an open source RAT (Remote Administration Tool) with a variety of functions. JPCERT/CC has confirmed that a group called APT10 used this tool in some targeted attacks against Japanese organisations.
Jolly Frog: Quasar Rat / Korplug
The decrypted module is the C# "QuasarRAT," which is injected into the "hncfinder.exe" process.
The Larva-24009 threat actor installs a PowerShell backdoor through LNK malware and subsequently maintains persistence by installing remote control tools such as QuasarRAT and UltraVNC.
Quasar RAT, un cheval de Troie d'accès à distance (RAT) bien connu, a récemment vu de nombreuses variantes et modifications utilisées dans des cyberattaques, en particulier par des groupes de menace comme BlindEagle et CoralRaider.
Quasar RAT, un cheval de Troie d'accès à distance (RAT) bien connu, a récemment vu de nombreuses variantes et modifications utilisées dans des cyberattaques, en particulier par des groupes de menace comme BlindEagle et CoralRaider.
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
The blog claims that this URL delivered a modified Quasar RAT payload which included the addition of SharpSploit, an opensource post-exploitation tool.
QuasarRAT v1.4.1.0 serves as the primary implant -- a full-featured .NET RAT with credential stealing via browser password databases, keylogging through the Gma.System.MouseKeyHook library, registry manipulation, and file management capabilities. A second variant, QuasarRAT v1.8.8 "Sentinel", was discovered packed with Costura and bundled with six DLLs providing HVNC (Hidden Virtual Network Computing), dedicated keylogging, and browser credential theft modules.
QuasarRAT v1.4.1.0 serves as the primary implant -- a full-featured .NET RAT with credential stealing via browser password databases, keylogging through the Gma.System.MouseKeyHook library, registry manipulation, and file management capabilities. A second variant, QuasarRAT v1.8.8 "Sentinel", was discovered packed with Costura and bundled with six DLLs providing HVNC (Hidden Virtual Network Computing), dedicated keylogging, and browser credential theft modules.
"Malware: Waizsar RAT, Mobzsar, Amphibeon, MumbaiDown, Quasar RAT"
Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike
"Another type of malware that the attackers attempted to use is Quasar RAT."
...застосовано... шкідливих програм: REMCOS RAT, QUASAR RAT, VENOM RAT, REMOTE UTILITIES та LUMMASTEALER.
...using remote access trojans (RAT) like RemcosRAT, QasarRat, AsyncRAT...; the installation of the RemcosRAT and Quasar Trojans was observed.
Exploited software
MITRE ATT&CK
Reporting
Cisco Talos reported that Chinese-speaking threat actor UAT-10147 targeted vulnerable internet-facing Windows IIS and Linux servers worldwide, using publicly disclosed one-day flaws to gain access and then deploying a broad post-compromise toolkit tied to SEO fraud and data theft. Talos said the group used AI-assisted workflows to automate reconnaissance, exploit validation, payload deployment, persistence, and operational documentation, and maintained infrastructure suggesting significant scale, including a target list of roughly 170,000 URLs. On compromised Windows systems, the actor used batch scripts, scheduled tasks, rogue user creation, EfsPotato, and Defender exclusions; on Linux, it relied on web shells and local privilege-escalation exploits to obtain root access. A central payload in the campaign was SPECTRE, a custom cross-platform backdoor for Windows and Linux that supports HTTP-based command and control, anti-analysis, process injection, credential access, and on Windows a BYOVD technique to reduce EDR visibility by unlinking kernel callbacks. On Linux, SPECTRE deployed a rootkit called Specter, disguised as acpi_pad.ko and persisted through a fraudulent systemd service to hide processes and modules and elevate privileges. Talos also observed Noodle RAT, QuasarRAT, Gh0stCringe, Meterpreter, and web shells in the same operations; prior research has linked Noodle RAT variants to multiple Chinese-speaking espionage and financially motivated clusters, including Linux samples that copy themselves to /tmp/CCCCCCCC, decrypt configuration with RC4 using the hardcoded key r0st@#$, and connect to attacker-controlled C2 servers.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Security researchers reported ongoing phishing activity by Larva-24009, a threat actor active since at least 2023, using email lures to compromise users and install malware. The campaign has targeted victims in South Korea as well as organizations and users internationally, with analysis published by AhnLab ASEC and echoed by other researchers including Cyble. The newly documented case adds to earlier disclosures from 2024 that linked the actor to similar email-based intrusion activity, indicating a sustained malware delivery operation rather than an isolated incident. Public reporting attributes the attacks to phishing emails crafted to trick recipients into opening malicious content, reinforcing the continued risk from socially engineered initial access campaigns aimed at broad regional and cross-border targets.
Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.