Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 87 IP / 185 hostnames
Quasar RAT is an open-source Windows remote access trojan written in .NET/C# and publicly available since 2015.
Profile source: Mallory opens in a new tabQuasarRAT
Quasar RAT is an open-source Windows remote access trojan written in .NET/C# and publicly available since 2015. It has been widely reused in criminal operations, opportunistic malware distribution, and state-linked intrusion sets, making it both a standalone malware family and a building block for derivative tools and customized implants. Security reporting has associated Quasar RAT usage with campaigns involving repository backdoors, phishing-delivered loaders, software supply-chain abuse, and post-compromise tooling in broader intrusions. It has also been used by actors including APT10/menuPass and has influenced or been cloned by later families such as AsyncRAT and VenomRAT; some operations have also deployed Golang reimplementations such as GOSAR.
Quasar RAT provides typical remote administration and surveillance capabilities for Windows victims. Documented functionality includes remote command execution, registry editing, webcam viewing, user and account-type enumeration, hidden-window execution, concealment of web requests from the user, and the ability to set files as hidden for defense evasion. Reporting also places Quasar-family implants in multi-stage chains that use reflective or in-memory loading, AMSI tampering, process injection, and persistence mechanisms such as services or scheduled execution, although some of those behaviors may be implemented by loaders or customized wrappers rather than the core public project itself.
Quasar RAT is commonly delivered as a downstream payload rather than the initial infection vector. Observed delivery chains include phishing and spearphishing lures, malicious archives, trojanized GitHub repositories, fake software projects, deceptive developer packages and extensions, and loader ecosystems that retrieve Quasar alongside stealers, miners, or other RATs. In several campaigns it appeared as one of multiple final payloads, providing redundant remote access after initial compromise.
The malware targets Windows systems and has appeared across a broad victim set, including governments, managed service providers, financial institutions, developers, and users targeted through tax, cryptocurrency, gaming-cheat, and software-development lures. Because Quasar RAT is open source and broadly adopted, its presence alone is not attributionally unique; it is frequently repurposed, modified, and embedded in larger intrusion workflows.
C2 tracking
Derp observations, rolling seven-day window
Samples
026f29238f31c880153a7520b37be3343729260364954d1c4ccad70f71e656ed 354a228046c31db339d4e382880c940c9afcac8999b159f17f888ffae9e86a52 a86a909eb06e486c66aca8772e494eb6cabf56d284a64e826af9ffe7d836df47 d87482a9fd086bf3d547c56aaeb2ffe01b2900bfe75f8576bb904e904b19cc8e 43ac6bf48fa000428a6249dace173b162e4ac4fe659e9db9d1a81e4f91b7ce2f dcf4aaf7a49a3c69b3d3ab0605b7b4e78d3d0db3739943ae421f4c3fd3c2c1f9 1be48ffa70d92f1e966d516f58ff3cabff9f09435b1660cde8795ed20de9aea9 29a6a47be402162b0fc02016fdd57ec309ad5f53ccf3b4a0db0d36dfe0b8d8cb 2ffa23170c381ba34fd0be44223e14ec5159f746a1277e31e3328f3f75577e6d 607e36215c1897a35631a1de9c0dbeb3d6520090af1c0c77fa021dc34e410e76 Reported operators
That same reporting identified new or expanded tooling, including HAYMAKER, SNUGRIDE, BUGJUICE, SOGU, and customized QUASARRAT.
01/2017: Downeks and Quasar RAT Used in Recent Targeted Attacks Against Governments β Unit42
Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.
Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
Quasar RAT (Trojan.Quasar): Commodity RAT that can be used to steal passwords and execute commands on an infected computer.
The attack chain, the company explained, initiated a multi-stage sequence that culminated in the deployment of an open-source remote access trojan named Quasar RAT.
The blog claims that this URL delivered a modified Quasar RAT payload which included the addition of SharpSploit, an opensource post-exploitation tool.
QuasarRAT v1.4.1.0 serves as the primary implant -- a full-featured .NET RAT with credential stealing via browser password databases, keylogging through the Gma.System.MouseKeyHook library, registry manipulation, and file management capabilities. A second variant, QuasarRAT v1.8.8 "Sentinel", was discovered packed with Costura and bundled with six DLLs providing HVNC (Hidden Virtual Network Computing), dedicated keylogging, and browser credential theft modules.
QuasarRAT v1.4.1.0 serves as the primary implant -- a full-featured .NET RAT with credential stealing via browser password databases, keylogging through the Gma.System.MouseKeyHook library, registry manipulation, and file management capabilities. A second variant, QuasarRAT v1.8.8 "Sentinel", was discovered packed with Costura and bundled with six DLLs providing HVNC (Hidden Virtual Network Computing), dedicated keylogging, and browser credential theft modules.
"Malware: Waizsar RAT, Mobzsar, Amphibeon, MumbaiDown, Quasar RAT"
Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike
TAG-144 leverages a range of commodity remote access trojans (RATs), including AsyncRAT, REMCOS RAT, DcRAT, njRAT, LimeRAT, QuasarRAT, BitRAT, and a Quasar variant known as BlotchyQuasar.
"Another type of malware that the attackers attempted to use is Quasar RAT."
...Π·Π°ΡΡΠΎΡΠΎΠ²Π°Π½ΠΎ... ΡΠΊΡΠ΄Π»ΠΈΠ²ΠΈΡ ΠΏΡΠΎΠ³ΡΠ°ΠΌ: REMCOS RAT, QUASAR RAT, VENOM RAT, REMOTE UTILITIES ΡΠ° LUMMASTEALER.
...using remote access trojans (RAT) like RemcosRAT, QasarRat, AsyncRAT...; the installation of the RemcosRAT and Quasar Trojans was observed.
βALUMINUM SARATOGA uses many openly available tools for its operations, includingβ¦ QuasarRatβ¦β
Exploited software
MITRE ATT&CK
Reporting
Decoded payload stages map to AsyncRAT, Quasar, and Remcos-style RAT detections alongside infostealer behavior.
The downstream payload activity maps to AsyncRAT, Quasar, and Remcos-style remote access tools alongside infostealer-like behavior.
The two final implants are a Gh0st RAT derivative with screen capture abilities connecting over port 6666, and a Quasar or AsyncRAT family .NET implant that patches the Antimalware Scan Interface before loading, connecting over port 6351.
The in-memory .NET assembly is a Quasar/AsyncRAT-family implant... The decrypted configuration yields the following indicators... C2 Host ouewop[.]com C2 Port 6351 Version Reach 2.0.1 Mutex 5sGEm6Q4eTNv.
a custom malware loader dubbed SADBRIDGE, which is designed to deploy a Golang-based reimplementation of Quasar RAT known as GOSAR.
Malware / Outils # ... Quasar RAT (rat) ...
That same reporting identified new or expanded tooling, including HAYMAKER, SNUGRIDE, BUGJUICE, SOGU, and customized QUASARRAT.
This technique mirrors tactics used by malware families like Agent Tesla, GuLoader, LokiBot, and Quasar RAT, which rely on the resource section to bury their payloads.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.