QUIC RAT is a highly selective Windows remote access trojan used as a final-stage implant in a 2026 software supply-chain intrusion involving trojanized DAEMON Tools Lite installers. It was delivered only after earlier-stage victim profiling and follow-on backdoor deployment, indicating use against targets assessed to be of particular intelligence value. Confirmed deployment was limited to a single Russian educational institution.
The malware is implemented in C++, heavily obfuscated with control-flow-flattening techniques, and statically linked with the WolfSSL library. It is notable for supporting an unusually broad set of command-and-control transports, including HTTP, TCP, UDP, WSS, DNS, QUIC, and HTTP/3, providing operators with flexible communications options and resilience. QUIC RAT also injects payloads into legitimate Windows processes, specifically notepad.exe and conhost.exe, to blend malicious activity with trusted processes and complicate detection.
Operational reporting places QUIC RAT in a staged intrusion chain in which broadly distributed compromised software first enabled host profiling, after which a smaller subset of victims received a lightweight backdoor and shellcode loader. QUIC RAT represented the most advanced payload in that chain and appears associated with a targeted cyber-espionage-oriented operation affecting organizations in sectors including government, science, manufacturing, retail, and education, with advanced activity concentrated in Russia, Belarus, and Thailand. No formal public attribution to a specific threat actor is established, although some artifacts elsewhere in the broader campaign suggested a possible Chinese-speaking operator.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The root cause of CVE-2026-8398 (classified under CWE-506: Embedded Malicious Code) is unauthorized access to AVB Disc Soft's build or distribution infrastructure. The attackers modified three core binaries within the DAEMON Tools Lite installation package. | Stage 4: Advanced Implant (QUIC RAT). In the most selective deployment, a C++ remote access trojan dubbed QUIC RAT is delivered. This implant injects itself into notepad.exe and conhost.exe and supports an unusually broad range of communication protocols: HTTP, UDP, TCP, WSS, QUIC, DNS, and HTTP/3.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following this profiling stage, the group selectively delivered the shellcoded loader BADFALL to facilitate hands-on-keyboard activity and bridge the deployment of the advanced QUIC RAT.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Traditional software supply chain compromise, the manipulation of source code or update/distribution mechanisms (T1195.002), remains rare.
The latest example is the compromise of Windows installers of the DAEMON Tools software to serve a lightweight backdoor, which then acts as a conduit for an implant dubbed QUIC RAT. What's more, the installers are distributed from the legitimate website of DAEMON Tools and are signed with digital certificates belonging to DAEMON Tools developers.
When launched, these components activate an implant that communicates with a malicious domain, env-check.daemontools[.]cc, to receive and execute shell commands.
Observed commands leveraged System.Net.WebClient to retrieve additional payloads from attacker infrastructure hosted at 38.180.107[.]76.
Windows Command Shell T1059.003 Execution cmd.exe исполняет команды C2
Because DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe are core components that execute automatically at system startup, the implanted code achieves persistence without needing to create additional scheduled tasks, registry keys, or services
QUIC RAT инжектирует пейлоады в notepad.exe и conhost.exe - Process Injection (T1055)
Because DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe are core components that execute automatically at system startup, the implanted code achieves persistence without needing to create additional scheduled tasks, registry keys, or services
QUIC RAT инжектирует пейлоады в notepad.exe и conhost.exe - Process Injection (T1055)
Payloads were written to temporary directories and executed immediately before deletion attempts were performed to reduce forensic visibility.
download a .NET-based information collector, harvesting system details such as language settings, running processes, and installed software.
download a .NET-based information collector, harvesting system details such as language settings, running processes, and installed software.
Upon execution, the modified binaries send an HTTP GET request to this domain containing the full computer name of the infected machine
Upon execution, the malware launched a dedicated thread responsible for beaconing to attacker-controlled infrastructure using HTTP GET requests.
Initial analysis found that it can inject payloads into the notepad.exe and conhost.exe processes and supports a variety of C2 communication protocols, including HTTP, UDP, TCP, WSS, QUIC, DNS, and HTTP/3.
Ingress Tool Transfer T1105 Command and Control Загрузка envchk.exe, cdg.exe, QUIC RAT
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Final-stage remote access implant written in C++ that supports multiple C2 protocols including HTTP, UDP, TCP, WSS, QUIC, DNS, and HTTP/3, and injects payloads into notepad.exe and conhost.exe for stealth.
A C++ remote access trojan delivered in the final stage of the DAEMON Tools Lite supply-chain attack. It injects into notepad.exe and conhost.exe and provides advanced remote access over multiple protocols including HTTP, UDP, TCP, WSS, QUIC, DNS, and HTTP/3, indicating an espionage-oriented implant designed to blend with legitimate traffic.
A C++-based remote access trojan used as an advanced follow-on payload in the DAEMON Tools supply chain compromise. It supports HTTP, HTTP/3, QUIC, TCP, UDP, WSS, and DNS communications, and was observed injecting payloads into legitimate processes such as notepad.exe and conhost.exe for stealth and defense evasion.
A remote access trojan payload delivered in the DAEMON Tools supply chain compromise. It was selectively deployed in a targeted intrusion against a Russian educational institution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.