QuiteRAT is a lightweight remote access trojan (RAT) associated with the North Korean Lazarus Group. It has been reported in campaigns exploiting Zoho ManageEngine ServiceDesk / ServiceDesk Plus vulnerability CVE-2022-47966 to compromise organizations including an internet backbone infrastructure company in Europe and healthcare entities in Europe and the United States. Cisco Talos described this activity as part of Lazarus infrastructure reuse across multiple campaigns.
QuiteRAT is based on the Qt framework and is assessed as related to, or an evolution/derivative of, Lazarus’s earlier MagicRAT family. Compared with MagicRAT, QuiteRAT has a smaller footprint, averaging roughly 4–5 MB versus much larger MagicRAT builds, due to fewer embedded Qt libraries and the absence of built-in persistence. Despite using Qt, it has no GUI.
Functionally, QuiteRAT is a fairly simple RAT used to maintain control over compromised networks. After execution, it performs host reconnaissance, sends preliminary system information to command-and-control (C2), and awaits tasking. Reported capabilities include arbitrary command execution via a child cmd.exe process. Observed reconnaissance commands included systeminfo piped to findstr Logon and ipconfig piped to findstr Suffix. It collects MAC addresses, IP addresses, and the current username, and uses them to compute an MD4-based victim identifier.
Its networking configuration, including C2 URLs and URI parameters, is stored using XOR with 0x78 followed by Base64 encoding. It communicates over HTTP GET and has been observed using parameters such as mailid, action (including inbox and sent), body, param, and session. It limits returned data chunks to 0x400 bytes and appends the marker "< No Pineapple! >" when output exceeds that size. Reported operational features include a sendmail command that causes the implant to sleep for a specified number of minutes and a receivemail command that switches to a secondary URL for commands or payload retrieval. An observed User-Agent was "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0".
QuiteRAT does not include a native persistence mechanism, but persistence was observed being established through registry/service creation commands that created a Windows service named WindowsNotification to launch c:\users\public\notify.exe.
In observed intrusions, exploitation of CVE-2022-47966 triggered download and execution of the payload via the Java runtime process. Talos reported use of a cURL command to retrieve the malware from hxxp://146[.]4[.]21[.]94/tmp/tmp/comp[.]dat and save it as c:\users\public\notify.exe, after which the Java process executed the implant. Reported indicators include SHA-256 ed8ec7a8dd089019cfd29143f008fa0951c56a35d73b2e1b274315152d0c0ee6 and infrastructure/URLs including 146[.]4[.]21[.]94, hxxp://146[.]4[.]21[.]94/tmp/tmp/comp[.]dat, hxxp://146[.]4[.]21[.]94/tmp/tmp/log[.]php, hxxp://146[.]4[.]21[.]94/tmp/tmp/logs[.]php, and hxxp://ec2-15-207-207-64[.]ap-south-1[.]compute[.]amazonaws[.]com/resource/main/rawmail[.]php.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In early 2023, Lazarus Group targeted CVE-2022-47966, a vulnerability in ManageEngine ServiceDesk Plus, which allowed them to execute arbitrary code on unpatched systems. | After gaining access, Lazarus deployed QuiteRAT, a lightweight malware variant, to maintain control over the compromised networks.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After gaining access, Lazarus deployed QuiteRAT, a lightweight malware variant, to maintain control over the compromised networks.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
In December 2023, Lazarus Group continued to exploit the notorious Log4Shell vulnerability (CVE-2021-44228), specifically targeting unpatched VMware Horizon servers... In early 2023, Lazarus Group targeted CVE-2022-47966... which allowed them to execute arbitrary code on unpatched systems.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight remote access trojan deployed by Lazarus Group after exploiting ManageEngine ServiceDesk Plus to maintain control of compromised networks.
Referenced as another Lazarus RAT family associated with use of non-traditional development frameworks (Qt).
QuiteRAT is a remote access trojan (RAT) deployed by the Lazarus Group to provide persistent access and control over compromised systems, often used in targeted attacks against critical infrastructure and healthcare organizations.
Qt-based remote access trojan used by Lazarus Group following exploitation of ManageEngine ServiceDesk; described as a smaller, easier-to-deploy variant/derivative of MagicRAT with similar capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.