Quasar RAT is an open-source Windows remote access trojan written in .NET/C# and publicly available since 2015. It has been widely reused in criminal operations, opportunistic malware distribution, and state-linked intrusion sets, making it both a standalone malware family and a building block for derivative tools and customized implants. Security reporting has associated Quasar RAT usage with campaigns involving repository backdoors, phishing-delivered loaders, software supply-chain abuse, and post-compromise tooling in broader intrusions. It has also been used by actors including APT10/menuPass and has influenced or been cloned by later families such as AsyncRAT and VenomRAT; some operations have also deployed Golang reimplementations such as GOSAR.
Quasar RAT provides typical remote administration and surveillance capabilities for Windows victims. Documented functionality includes remote command execution, registry editing, webcam viewing, user and account-type enumeration, hidden-window execution, concealment of web requests from the user, and the ability to set files as hidden for defense evasion. Reporting also places Quasar-family implants in multi-stage chains that use reflective or in-memory loading, AMSI tampering, process injection, and persistence mechanisms such as services or scheduled execution, although some of those behaviors may be implemented by loaders or customized wrappers rather than the core public project itself.
Quasar RAT is commonly delivered as a downstream payload rather than the initial infection vector. Observed delivery chains include phishing and spearphishing lures, malicious archives, trojanized GitHub repositories, fake software projects, deceptive developer packages and extensions, and loader ecosystems that retrieve Quasar alongside stealers, miners, or other RATs. In several campaigns it appeared as one of multiple final payloads, providing redundant remote access after initial compromise.
The malware targets Windows systems and has appeared across a broad victim set, including governments, managed service providers, financial institutions, developers, and users targeted through tax, cryptocurrency, gaming-cheat, and software-development lures. Because Quasar RAT is open source and broadly adopted, its presence alone is not attributionally unique; it is frequently repurposed, modified, and embedded in larger intrusion workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat Details and IOCs Malware: ... Quasar RAT, QuasarRAT ...
The vulnerability, assigned the CVE identifier CVE-2024-4577... an argument injection vulnerability in PHP affecting Windows-based systems running in CGI mode
17 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
That same reporting identified new or expanded tooling, including HAYMAKER, SNUGRIDE, BUGJUICE, SOGU, and customized QUASARRAT.
01/2017: Downeks and Quasar RAT Used in Recent Targeted Attacks Against Governments – Unit42
Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.
Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
Quasar RAT (Trojan.Quasar): Commodity RAT that can be used to steal passwords and execute commands on an infected computer.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
The infection begins on fraudulent websites that copy the look of the Indian Income Tax Department, each using an “/incometax” path and a fabricated compliance notice.
Socket has published research findings describing a Go module that posed as a DNS and subdomain scanner while acting as a first-stage Windows malware loader.
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com.
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com, decodes it with certutil, and runs the result with execution-policy bypass.
a Quasar or AsyncRAT family .NET implant that patches the Antimalware Scan Interface before loading
Lure themes span MetaMask and Trust Wallet integrations, seed-phrase utilities, Binance and PayPal automation, Telegram and Discord bots, and game cheats for PUBG, Valorant, and Escape from Tarkov.
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
The chain finishes by injecting two payloads into svchost.exe processes across every active user session
The injector enumerates all active terminal sessions and, for each one, spawns a suspended svchost.exe process under a duplicated token whose session ID has been reassigned to match the target session.
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
Socket describes the decoded script as a multi-layer loader using Base64 encoding and XOR decryption.
The malware then fetches a file from its infrastructure that looks like an ordinary JPEG image but actually hides multiple encrypted payloads appended after the picture data.
The attackers built their lure using authentic looking government branding, including references to the Ministry of Finance and the Enforcement Division, to make the fake notice feel credible.
With elevation confirmed, the downloader prepares its staging directory under C:\Program Files\Windows Media Player, a legitimate-looking path... copies its own running binary into the working directory under the name Mixed Reality.exe.
The chain finishes by injecting two payloads into svchost.exe processes across every active user session
The injector enumerates all active terminal sessions and, for each one, spawns a suspended svchost.exe process under a duplicated token whose session ID has been reassigned to match the target session.
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com, decodes it with certutil, and runs the result... Socket describes the decoded script as a multi-layer loader using Base64 encoding and XOR decryption.
The loader extracts it into a directory named to resemble a legitimate Microsoft Photos install and launches Microsoft.exe from that path with a hidden window.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
With the payload prepared, the injector enumerates running processes and locates svchost.exe as its injection target.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The payload chain... communicates with Telegram or other public web services.
Rather than hardcoding a payload URL, the resolver retrieves text from public platforms, searches it for the marker string 'LastW,' then decrypts the trailing blob with a hardcoded key to recover the actual download location. Primary dead drops include Pastebin and a paste service called Rlim, with fallbacks across YouTube, Instagram, Telegram, Google Docs, and GitCode.
425 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
186 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT-family payload identified in decoded stages of the campaign.
Remote access trojan-style payload family associated with downstream activity in the campaign.
Mentioned as a possible family identification for the .NET implant alongside AsyncRAT; it is not conclusively identified as the deployed payload in the content.
A .NET remote access trojan loaded entirely in memory after AMSI patching and native CLR hosting. It is identified as a Quasar/AsyncRAT-family implant with encrypted configuration and a separate C2 channel for resilient access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.