Skip to content

QuasarRAT

Quasar RAT is a Windows-focused .NET remote-access trojan that provides an operator-controlled command-and-control implant on compromised hosts.

Profile source: Mallory opens in a new tab

QuasarRAT

Family profile

Quasar RAT is a Windows-focused .NET remote-access trojan that provides an operator-controlled command-and-control implant on compromised hosts. It can obtain passwords stored by common web browsers, modify the Windows Registry, and maintain persistence across reboot through scheduled tasks. Quasar RAT has been deployed on compromised IIS servers by the Chinese-speaking financially motivated actor UAT-10147, which used it alongside web shells, BadIIS, Gh0stCringe, and other post-exploitation tooling; observed activity included targeting of internet-facing servers across government, education, media, technology, and gaming organizations. It has also appeared in campaigns associated with Molerats and has communicated with infrastructure linked to Sable Squirrel. Observed delivery chains include phishing-distributed malicious RAR archives exploiting CVE-2025-8088 and social-engineering campaigns using Microsoft OneNote documents containing embedded payloads.

Capabilities

  • Credential Theft
  • Persistence

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
157 IP / 200 hostnames

Leading locations

  • US100
  • DE29
  • CN28
  • NL28
  • GB15
  • HK14
  • RU13
  • FR11
  • SG8
  • KR7
  • LU5
  • MD4

Leading providers

  • Cloudflare, Inc.47
  • OOO GETWIFI12
  • Omegatech LTD11
  • Amazon.com, Inc.10
  • Hangzhou Alibaba Advertising Co.,Ltd.9
  • FEMO IT SOLUTIONS LIMITED8

Infrastructure traits

  • Hosting 245
  • Anycast 53
  • Proxy 2
  • Residential Proxy 2
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

28 named in public reporting
UAT-10147

“Its broader toolkit includes BadIIS, QuasarRAT, Gh0stCringe, Noodle RAT, Meterpreter, and multiple members of the Potato privilege escalation family.”

Sable Squirrel

к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT

Molerats

Quasar RAT: Hashes (SHA-256 + SHA-1) ... Domains Lynsub[.]com IPs 193.160.32.118

Patchwork

They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe.

Aluminum Saratoga

ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat

Kimsuky

In 2019, a suspected TA406 operator uploaded several files to VirusTotal (NavRAT, QuasarRAT and BabyShark downloader).

menuPass

While an ISO file was also used in this attack, the payload is a different Remote Access Trojan, “Quasar RAT”.

Cloud Hopper

Attackers also installed the QuasarRAT open-source backdoor and novel Backdoor.Hartip tool to continue surveillance on victims’ systems.

Water Basilisk

In some cases, the final stage PowerShell script contained up to seven various RATs. These are typically NjRat, BitRat, Nanocore RAT, QuasarRat, LimeRat, and Warzone.

DDGroup

all of them have been associated with off-the-shelf malware like QuasarRAT, BitRat, and similar.

APT33

Quasar is an open source RAT (Remote Administration Tool) with a variety of functions. JPCERT/CC has confirmed that a group called APT10 used this tool in some targeted attacks against Japanese organisations.

Gorgon Group

Quasar is an open source RAT (Remote Administration Tool) with a variety of functions. JPCERT/CC has confirmed that a group called APT10 used this tool in some targeted attacks against Japanese organisations.

DustySky

Quasar is an open source RAT (Remote Administration Tool) with a variety of functions. JPCERT/CC has confirmed that a group called APT10 used this tool in some targeted attacks against Japanese organisations.

TA410

Jolly Frog: Quasar Rat / Korplug

KONNI

The decrypted module is the C# "QuasarRAT," which is injected into the "hncfinder.exe" process.

Larva-24009

The Larva-24009 threat actor installs a PowerShell backdoor through LNK malware and subsequently maintains persistence by installing remote control tools such as QuasarRAT and UltraVNC.

CoralRaider

Quasar RAT, un cheval de Troie d'accès à distance (RAT) bien connu, a récemment vu de nombreuses variantes et modifications utilisées dans des cyberattaques, en particulier par des groupes de menace comme BlindEagle et CoralRaider.

APT-C-36

Quasar RAT, un cheval de Troie d'accès à distance (RAT) bien connu, a récemment vu de nombreuses variantes et modifications utilisées dans des cyberattaques, en particulier par des groupes de menace comme BlindEagle et CoralRaider.

SilverTerrier

The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.

TA429

The blog claims that this URL delivered a modified Quasar RAT payload which included the addition of SharpSploit, an opensource post-exploitation tool.

DarkCasino

QuasarRAT v1.4.1.0 serves as the primary implant -- a full-featured .NET RAT with credential stealing via browser password databases, keylogging through the Gma.System.MouseKeyHook library, registry manipulation, and file management capabilities. A second variant, QuasarRAT v1.8.8 "Sentinel", was discovered packed with Costura and bundled with six DLLs providing HVNC (Hidden Virtual Network Computing), dedicated keylogging, and browser credential theft modules.

Water Hydra

QuasarRAT v1.4.1.0 serves as the primary implant -- a full-featured .NET RAT with credential stealing via browser password databases, keylogging through the Gma.System.MouseKeyHook library, registry manipulation, and file management capabilities. A second variant, QuasarRAT v1.8.8 "Sentinel", was discovered packed with Costura and bundled with six DLLs providing HVNC (Hidden Virtual Network Computing), dedicated keylogging, and browser credential theft modules.

CTG-5938

Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike

GALLIUM

"Another type of malware that the attackers attempted to use is Quasar RAT."

UAC-0050

...застосовано... шкідливих програм: REMCOS RAT, QUASAR RAT, VENOM RAT, REMOTE UTILITIES та LUMMASTEALER.

Red Akodon

...using remote access trojans (RAT) like RemcosRAT, QasarRat, AsyncRAT...; the installation of the RemcosRAT and Quasar Trojans was observed.

Exploited software

Vulnerabilities linked to QuasarRAT

15 CVEs

MITRE ATT&CK

QuasarRAT in ATT&CK

108 distinct techniques

Techniques

108 techniques
T1071 Application Layer Protocol T1070 Indicator Removal T1053 Scheduled Task/Job T1059 Command and Scripting Interpreter T1036 Masquerading T1105 Ingress Tool Transfer T1190 Exploit Public-Facing Application T1036.005 Match Legitimate Resource Name or Location T1053.005 Scheduled Task T1071.001 Web Protocols T1588.002 Tool T1041 Exfiltration Over C2 Channel T1059.003 Windows Command Shell T1608 Stage Capabilities T1543.003 Windows Service T1562 Impair Defenses T1584 Compromise Infrastructure T1006 Direct Volume Access T1204 User Execution T1566 Phishing T1566.001 Spearphishing Attachment T1555.003 Credentials from Web Browsers T1112 Modify Registry T1082 System Information Discovery T1555 Credentials from Password Stores T1059.005 Visual Basic T1564.001 Hidden Files and Directories T1566.004 Spearphishing Voice T1057 Process Discovery T1529 System Shutdown/Reboot T1056.001 Keylogging T1564.003 Hidden Window T1548.002 Bypass User Account Control T1027 Obfuscated Files or Information T1573 Encrypted Channel T1547.001 Registry Run Keys / Startup Folder T1489 Service Stop T1090.003 Multi-hop Proxy T1574.001 DLL T1069 Permission Groups Discovery T1033 System Owner/User Discovery T1021.001 Remote Desktop Protocol T1083 File and Directory Discovery T1219 Remote Access Tools T1113 Screen Capture T1059.001 PowerShell T1055 Process Injection T1125 Video Capture T1090 Proxy T1564 Hide Artifacts T1543 Create or Modify System Process T1567.002 Exfiltration to Cloud Storage T1055.012 Process Hollowing T1140 Deobfuscate/Decode Files or Information T1570 Lateral Tool Transfer T1046 Network Service Discovery T1021.003 Distributed Component Object Model T1095 Non-Application Layer Protocol T1568 Dynamic Resolution T1189 Drive-by Compromise T1012 Query Registry T1218.001 Compiled HTML File T1203 Exploitation for Client Execution T1068 Exploitation for Privilege Escalation T1539 Steal Web Session Cookie T1218.004 InstallUtil T1497 Virtualization/Sandbox Evasion T1560 Archive Collected Data T1620 Reflective Code Loading T1566.002 Spearphishing Link T1195 Supply Chain Compromise T1204.002 Malicious File T1027.013 Encrypted/Encoded File T1583.001 Domains T1574 Hijack Execution Flow T1102.001 Dead Drop Resolver T1562.001 Disable or Modify Tools T1027.003 Steganography T1134.002 Create Process with Token T1106 Native API T1027.007 Dynamic API Resolution T1573.001 Symmetric Cryptography T1070.004 File Deletion T1027.002 Software Packing T1078 Valid Accounts T1027.009 Embedded Payloads T1055.002 Portable Executable Injection T1016 System Network Configuration Discovery T1553.002 Code Signing T1021 Remote Services T1592 Gather Victim Host Information T1497.001 System Checks T1657 Financial Theft T1087 Account Discovery T1001 Data Obfuscation T1547 Boot or Logon Autostart Execution T1134.001 Token Impersonation/Theft T1573.002 Asymmetric Cryptography T1614 System Location Discovery T1090.004 Domain Fronting T1567 Exfiltration Over Web Service T1571 Non-Standard Port T1588.004 Digital Certificates T1552.001 Credentials In Files T1059.007 JavaScript T1553.005 Mark-of-the-Web Bypass T1021.005 VNC T1218.005 Mshta

Reporting

Research mentioning QuasarRAT

Aug 20
Talosintelligence Other

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

Cisco Talos reported that Chinese-speaking threat actor UAT-10147 targeted vulnerable internet-facing Windows IIS and Linux servers worldwide, using publicly disclosed one-day flaws to gain access and then deploying a broad post-compromise toolkit tied to SEO fraud and data theft. Talos said the group used AI-assisted workflows to automate reconnaissance, exploit validation, payload deployment, persistence, and operational documentation, and maintained infrastructure suggesting significant scale, including a target list of roughly 170,000 URLs. On compromised Windows systems, the actor used batch scripts, scheduled tasks, rogue user creation, EfsPotato, and Defender exclusions; on Linux, it relied on web shells and local privilege-escalation exploits to obtain root access. A central payload in the campaign was SPECTRE, a custom cross-platform backdoor for Windows and Linux that supports HTTP-based command and control, anti-analysis, process injection, credential access, and on Windows a BYOVD technique to reduce EDR visibility by unlinking kernel callbacks. On Linux, SPECTRE deployed a rootkit called Specter, disguised as acpi_pad.ko and persisted through a fraudulent systemd service to hide processes and modules and elevate privileges. Talos also observed Noodle RAT, QuasarRAT, Gh0stCringe, Meterpreter, and web shells in the same operations; prior research has linked Noodle RAT variants to multiple Chinese-speaking espionage and financially motivated clusters, including Linux samples that copy themselves to /tmp/CCCCCCCC, decrypt configuration with RC4 using the hardcoded key r0st@#$, and connect to attacker-controlled C2 servers.

Aug 20
Talosintelligence Other

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Aug 19
Cyberveille

UAT-10147 déploie SPECTRE : implant multiplateforme avec rootkit Linux et capacités BYOVD | CyberVeille

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 3
Malware News

Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor - Malware Analysis - Malware Analysis, News and Indicators

Security researchers reported ongoing phishing activity by Larva-24009, a threat actor active since at least 2023, using email lures to compromise users and install malware. The campaign has targeted victims in South Korea as well as organizations and users internationally, with analysis published by AhnLab ASEC and echoed by other researchers including Cyble. The newly documented case adds to earlier disclosures from 2024 that linked the actor to similar email-based intrusion activity, indicating a sustained malware delivery operation rather than an isolated incident. Public reporting attributes the attacks to phishing emails crafted to trick recipients into opening malicious content, reinforcing the continued risk from socially engineered initial access campaigns aimed at broad regional and cross-border targets.

Aug 2
Ahnlab Asec

Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor - ASEC

Jul 30
Splunk Research

Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content

Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.