Pulsar RAT is a modular .NET remote access trojan targeting Windows systems. It has been characterized as an open-source, Quasar RAT-derived tool and is deployed through multi-stage, heavily obfuscated loaders that favor PowerShell, Donut-generated shellcode, reflective loading, and in-memory process injection to reduce on-disk artifacts. Documented delivery includes typosquatted malicious npm packages, where post-install execution can recover a steganographically concealed payload and deploy the RAT. Pulsar RAT has also appeared alongside browser-extension-based banking malware in Brazil-focused KREMLIN/REF9334 activity and in other commodity-malware campaigns.
The RAT supports interactive remote control, remote command execution, file operations, credential theft from Chromium- and Firefox-family browsers, keylogging, and collection of screen, webcam, and microphone data. It can steal cryptocurrency-wallet data and replace cryptocurrency addresses in the clipboard. Collected information may be compressed and exfiltrated through attacker-controlled infrastructure or common messaging services. Observed variants use anti-virtualization and anti-debugging checks, AMSI, ETW, and Windows Lockdown Policy bypasses, process injection, and watchdog behavior to hinder analysis and maintain execution. Persistence has been observed through user-level Run-key entries and scheduled tasks, with some loaders attempting UAC bypass. C2 communications have been observed using encrypted protocols and MessagePack-based messaging.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Documented REF9334 campaigns used PULSAR versions 1.6.6/1.7.3 in June 2025, PULSAR in the Codecaudiog B and Acrobat campaigns, and PULSAR 2.4.5 in the April 2026 Cremeb campaign.
The actor-hosted payload inventory maps plsr_instllr_1804.exe to Pulsar RAT, while the consolidated table lists PulsarRAT version 1.5.1.
39 distinct techniques documented for this family, organized by ATT&CK tactic.
GUID-encoded shellcode — 973 KB of x64 shellcode stored as 60,820 Windows GUIDs in the PE .rdata section, evading signature-based detection
DLL sideloading de SentinelMemoryScanner.exe; leurre Adobe Framesync.
“Defense Evasion T1070.004 Indicator Removal: File Deletion” and “writes it temporarily to disk… and then deletes the script.”
T1140 Deobfuscate/Decode Files GUID-to-bytes decoding at runtime
Anti-VM CheckForVMwareAndVirtualBox , VMware/VirtualBox/QEMU/Parallels strings
Category Evidence Screen capture SharpDX , SharpDX.Direct3D11 , SharpDX.DXGI , SharpDX.D3DCompiler
Clipboard hijack : Monitors clipboard continuously; replaces any recognized crypto address with attacker's address
Category Evidence Audio NAudio.Core , NAudio.Wasapi , Error stopping audio
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access Trojan additionally distributed in some KREMLIN-linked campaigns.
A remote-access trojan associated with earlier KREMLIN campaign infrastructure and delivered alongside malicious browser extensions.
A remote-access trojan associated with earlier KREMLIN-related campaigns through listed command-and-control endpoints, including Acrobat and Cremeb campaign infrastructure. The content does not provide further behavioral details.
An off-the-shelf remote-access trojan distributed in campaigns attributed to the KREMLIN operators.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.