Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GOSAR is a Golang-based reimplementation of QUASAR, deployed by SADBRIDGE, with support for Windows and Linux.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
SADBRIDGE stores encrypted stages with a .log extension; GOSAR encrypts plugins, collected logs, and keylogger/clipboard data.
Campaign samples were hosted on landing pages masquerading as Telegram or the Opera GX browser, and installers bundled legitimate applications with malicious DLLs.
SADBRIDGE employs PoolParty, APC queues, and token manipulation techniques for process injection.
SADBRIDGE uses APC injection to queue decrypted GOSAR shellcode into a newly created process thread; the GOSAR plugin component also queues APCs in suspended msiexec.exe.
GOSAR sets a global Windows hook with SetWindowsHookEx and WH_KEYBOARD_LL to intercept and record low-level keyboard events.
GOSAR's Capture.dll captures the victim desktop as JPEG images, while its HVNC component supports remote screen retrieval.
The current version we have only processes a GET request to the URI /security.js , responding with the string callback();
GOSAR executes plugins that are downloaded from C2, encrypted on disk at C:\ProgramData\policy-err.log, then decrypted and loaded.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Golang-based reimplementation of Quasar RAT mentioned only as a payload deployed by SADBRIDGE in a separate intrusion set.
A Golang reimplementation of QUASAR that functions as a multi-platform remote access trojan/backdoor for Windows and Linux. It supports system information theft, screenshots, command execution, keylogging, clipboard logging, plugin execution, HVNC, screen capture, process/service management, and encrypted logging over TCP/TLS C2.
Cross-platform remote-access trojan derived from QUASAR functionality. It communicates over TCP/TLS and supports system reconnaissance, command execution, screenshots, keylogging, clipboard logging, process and service control, encrypted logging, plugin execution, hidden VNC, and hidden RDP-related capabilities. It also creates a firewall rule and an incomplete HTTP listener on ports 51756-51776.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.