QuasarRAT is an open-source .NET remote access trojan written in C# that has been widely used in both commodity cybercrime and targeted intrusion activity since at least 2015. Derived from xRAT and commonly referred to as Quasar or Quasar RAT, it provides attackers with persistent remote control of Windows systems and remains prevalent in incident response cases and malware telemetry.
QuasarRAT supports a broad set of post-compromise capabilities associated with full remote administration. Documented functions include registry editing, keylogging, password theft, file exfiltration, webcam access, hiding process windows, making web requests less visible to the user, and host profiling such as enumerating usernames and account type. It is also used as a downstream implant after multi-stage loaders and can be deployed alongside other RATs or stealers to maintain redundant access.
The malware commonly establishes persistence using a Run key when installed without elevated privileges and a Scheduled Task when administrative privileges are available. Defenders have also noted predictable operational artifacts in many deployments, including a default client port frequently left unchanged by operators, GUID-like mutex formats, and a hard-coded user-agent string that can aid hunting. Some observed variants or related loaders patch AMSI before loading the .NET implant, and Quasar-family payloads have also been observed executing via process injection or reflective in-memory loading.
QuasarRAT is used by a diverse set of threat actors rather than a single exclusive operator. Reported users include Larva-24009, BlindEagle, CoralRaider, menuPass/APT10 in customized form, and North Korea-linked Konni activity, while other financially motivated and espionage-oriented campaigns have also deployed it. It has appeared in operations targeting enterprises, managed services environments, financial institutions, government and defense-related organizations including NATO-linked targets, and developer or DevOps-focused victims in more recent activity.
Delivery is most often tied to phishing-led intrusion chains and staged malware distribution. Observed infection paths include malicious LNK attachments, ZIP archives, JavaScript or batch-script loaders, trojanized repositories and fake software projects, and DLL sideloading through signed executables. In many campaigns QuasarRAT is not the initial payload but a later-stage implant delivered by PowerShell, .NET loaders, or custom downloaders after initial execution and persistence are established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat Details and IOCs Malware: ... Quasar RAT, QuasarRAT ...
The vulnerability, assigned the CVE identifier CVE-2024-4577... an argument injection vulnerability in PHP affecting Windows-based systems running in CGI mode
19 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Larva-24009 threat actor installs a PowerShell backdoor through LNK malware and subsequently maintains persistence by installing remote control tools such as QuasarRAT and UltraVNC.
Quasar RAT, un cheval de Troie d'accès à distance (RAT) bien connu, a récemment vu de nombreuses variantes et modifications utilisées dans des cyberattaques, en particulier par des groupes de menace comme BlindEagle et CoralRaider.
Quasar RAT, un cheval de Troie d'accès à distance (RAT) bien connu, a récemment vu de nombreuses variantes et modifications utilisées dans des cyberattaques, en particulier par des groupes de menace comme BlindEagle et CoralRaider.
That same reporting identified new or expanded tooling, including HAYMAKER, SNUGRIDE, BUGJUICE, SOGU, and customized QUASARRAT.
01/2017: Downeks and Quasar RAT Used in Recent Targeted Attacks Against Governments – Unit42
Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Socket has published research findings describing a Go module that posed as a DNS and subdomain scanner while acting as a first-stage Windows malware loader.
Les analystes ont également observé des chaînes d'infection sophistiquées impliquant un accès initial par hameçonnage qui conduit à l'exécution de scripts PowerShell pour le déploiement d'autres payload.
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
Either the installer is run with administrative privileges, in which case a Scheduled Task is created.
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com.
Les analystes ont également observé des chaînes d'infection sophistiquées impliquant un accès initial par hameçonnage qui conduit à l'exécution de scripts PowerShell pour le déploiement d'autres payload.
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
Either the installer is run with administrative privileges, in which case a Scheduled Task is created.
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
Either the installer is run with administrative privileges, in which case a Scheduled Task is created.
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
Socket describes the decoded script as a multi-layer loader using Base64 encoding and XOR decryption.
The malware then fetches a file from its infrastructure that looks like an ordinary JPEG image but actually hides multiple encrypted payloads appended after the picture data.
Le logiciel malveillant est principalement distribué par le biais de courriels de spear-phishing contenant des pièces jointes ou des liens malveillants, souvent en usurpant l'identité d'entités légitimes.
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com, decodes it with certutil, and runs the result... Socket describes the decoded script as a multi-layer loader using Base64 encoding and XOR decryption.
The loader extracts it into a directory named to resemble a legitimate Microsoft Photos install and launches Microsoft.exe from that path with a hidden window.
The builder shows three default ports (6606, 7707, 8808) when assembling a new AsyncRAT client... users can input the C2 address, to which the AsyncRAT client will establish a connection upon successful infection.
Rather than hardcoding a payload URL, the resolver retrieves text from public platforms, searches it for the marker string 'LastW,' then decrypts the trailing blob with a hardcoded key to recover the actual download location. Primary dead drops include Pastebin and a paste service called Rlim, with fallbacks across YouTube, Instagram, Telegram, Google Docs, and GitCode.
1,013 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
192 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used by the threat actor to maintain persistence and remotely control infected systems.
Open-source C# RAT providing full remote control, registry editing, keylogging, password theft, and file exfiltration. Commonly delivered via malicious RTF/Office documents and PowerShell payload downloads.
An open-source .NET RAT with client-server architecture used for remote access and credential theft, including developer and CI/CD secrets in newer campaigns.
RAT-family payload identified in decoded stages of the campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.