Quasar RAT is a Windows-focused .NET remote-access trojan that provides an operator-controlled command-and-control implant on compromised hosts. It can obtain passwords stored by common web browsers, modify the Windows Registry, and maintain persistence across reboot through scheduled tasks. Quasar RAT has been deployed on compromised IIS servers by the Chinese-speaking financially motivated actor UAT-10147, which used it alongside web shells, BadIIS, Gh0stCringe, and other post-exploitation tooling; observed activity included targeting of internet-facing servers across government, education, media, technology, and gaming organizations. It has also appeared in campaigns associated with Molerats and has communicated with infrastructure linked to Sable Squirrel. Observed delivery chains include phishing-distributed malicious RAR archives exploiting CVE-2025-8088 and social-engineering campaigns using Microsoft OneNote documents containing embedded payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
In this blog post, I’ll be diving into the technical details of the WinRAR vulnerability, identified as CVE-2025-8088. This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw. | Quasar RAT The RAR archive contains text files and an Alternate Data Stream (ADS) linked to a Quasar RAT executable.
Researchers observed attackers leveraging Zerologon, or CVE-2020-1472, a Microsoft zero-day elevation-of-privilege vulnerability first disclosed and patched on Aug. 11. The flaw—which stems from the Netlogon Remote Protocol available on Windows domain controllers–allows attackers to spoof a domain controller account and then use it to steal domain credentials, take over the domain and completely compromise all Active Directory identity services. | Attackers also installed the QuasarRAT open-source backdoor and novel Backdoor.Hartip tool to continue surveillance on victims’ systems.
These attacks use dcRAT and QuasarRAT for Windows delivered via malicious documents exploiting CVE-2017-11882 — a memory corruption vulnerability in Microsoft Office... A typical infection would consist of a malicious document, such as an RTF file exploiting CVE-2017-11882, a stack overflow vulnerability that enables arbitrary code execution on a vulnerable version of Microsoft Office. | The attack phase consists of deploying RAT payloads, such as DcRAT and QuasarRAT, to the victim’s endpoint.
Both RTFs exploited CVE-2012-0158 and acted as downloaders to ultimately deliver the QuasarRAT malware family.
Among these tricks are using right-to-left override to obscure the attachments’ real extension, email attachments disguised as RAR self-extracting archives, and a combination of a specially crafted Word document carrying a CVE-2017-0199 exploit. | We have detected three different strains of .NET malware in these campaigns: Quasar RAT, Sobaken RAT, and a custom-made RAT called Vermin.
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Threat Details and IOCs Malware: ... Quasar RAT, QuasarRAT ...
The vulnerability, assigned the CVE identifier CVE-2024-4577... an argument injection vulnerability in PHP affecting Windows-based systems running in CGI mode
28 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Its broader toolkit includes BadIIS, QuasarRAT, Gh0stCringe, Noodle RAT, Meterpreter, and multiple members of the Potato privilege escalation family.”
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
Quasar RAT: Hashes (SHA-256 + SHA-1) ... Domains Lynsub[.]com IPs 193.160.32.118
They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe.
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
In 2019, a suspected TA406 operator uploaded several files to VirusTotal (NavRAT, QuasarRAT and BabyShark downloader).
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale.
Using the secondary batch script to silently execute Quasar RAT and establish persistence using a deceptive scheduled task named "Google Chrome Start"
In one case, the threat actor is said to have successfully exploited a website and collected information about the victim host using Linux commands.
Using the secondary batch script to silently execute Quasar RAT and establish persistence using a deceptive scheduled task named "Google Chrome Start"
This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw.
establish persistence using a deceptive scheduled task named "Google Chrome Start"
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
часть инфраструктуры Sable Squirrel используется для работы малвари: к доменам хак-группы обращались более 31 000 образцов вредоносов... некоторые сайты одновременно показывали посетителям спортивные трансляции и работали в качестве управляющих серверов для малвари.
1,258 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of UAT-10147’s broader toolkit; no further functional details are provided.
Remote access trojan observed using Sable Squirrel-controlled dropcatch domains as command-and-control infrastructure; one reclaimed domain, cel-robox[.]com, was specifically turned into a Quasar RAT C2 server.
A remote access trojan downloaded and silently executed by the actor, with persistence established via a deceptive scheduled task named "Google Chrome Start."
Remote access trojan deployed on Windows systems during post-compromise activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.