Researchers and incident responders have documented continued abuse of Quasar RAT and related malware such as AsyncRAT across espionage, phishing, and commodity malware operations. Quasar, an open-source remote administration tool, has been used by multiple threat actors including APT10 and operators targeting Ukrainian government institutions, where it appeared alongside Sobaken RAT and the custom Vermin backdoor to steal sensitive documents. JPCERT/CC reported that Quasar evolved into a broader Quasar Family that includes derivatives such as XPCTRA, CinaRAT, Void-RAT, and AsyncRAT, with protocol, encryption, and configuration changes complicating detection and attribution.
Recent technical analyses show the malware remains active in varied delivery chains and is often bundled or customized to evade scrutiny. One sample posing as a Chaos Ransomware builder was found to contain a clean ransomware builder alongside a hidden Quasar RAT payload embedded with Celesty Binder, with decrypted configuration revealing C2 66.63.167.164:55640, mutex QSR_MUTEX_M6ajmD3hhoJo7CTsvN, and persistence-related strings. Separate AsyncRAT campaigns used GitHub-hosted payloads, spoofed Thailand Pass lures, ISO/VBScript/PowerShell stages, process injection into aspnet_compiler.exe, scheduled-task persistence, antivirus checks, and credential theft. Network defenders have also been warned that Quasar, AsyncRAT, and other RATs frequently use custom non-HTTP/S C2 protocols over TCP with encryption, making heuristic traffic analysis and protocol-aware detection critical.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
15 events from the most recent confirmed update back to the earliest known activity.
OpenAnalysis analyzed a malware sample published on April 13, 2023 that masqueraded as a Chaos Ransomware builder but was actually bundled with Quasar RAT using Celesty Binder. The researchers extracted both the clean Chaos builder and the Quasar payload and decrypted the RAT configuration, revealing C2 endpoint 66.63.167.164:55640 and related settings.
K7 Labs reported that the GitHub repository NEW received two new PE files on January 31, 2021. The additions were assessed as possible preparation for further AsyncRAT-related campaigns.
K7 Labs found that the AsyncRAT payload used an SSL certificate with subject CN=AsyncRAT Server that became valid on January 17, 2021. The malware used the certificate for secure C2 communications.
K7 Labs reported that the GitHub account hbankers, described as managed by Mohamed-Sayed, was created on January 8, 2021. The account was later tied to hosting malware-related binaries for an AsyncRAT campaign.
JPCERT/CC identified 76 Quasar Family command-and-control server IP addresses as of November 2020. The finding indicated continued operational activity by Quasar-derived malware across multiple countries.
JPCERT/CC reported that Quasar version 1.4 was released in June 2020. The release introduced Protocol Buffers for serialization and TLS 1.2 for encrypted communications.
At JSAC 2020 on January 17, 2020, JPCERT/CC presented cyber incidents and attack trends observed during 2019. The presentation highlighted targeted attacks using generic tools including QuasarRAT and referenced APT10 activity involving it.
ESET first publicly reported the attackers' activities in January 2018. The campaign had already affected a few hundred victims across Ukrainian organizations.
ESET said it had tracked the espionage campaign targeting Ukrainian government institutions since mid-2017. The operation used Quasar RAT, Sobaken RAT, and Vermin to spy on victims and steal documents.
Zscaler reported that Remcos RAT first appeared on hacking forums in late 2016. It later saw use by both cybercriminals and APT actors.
Zscaler noted that Crimson RAT was used in attacks against Indian diplomatic and military resources in 2016. The malware was delivered through phishing and used custom non-HTTP/S communications.
ESET reported that the custom .NET backdoor Vermin first appeared in mid-2016. It later became one of three RATs used in the Ukrainian espionage campaign.
ESET traced threat actors' use of Quasar RAT binaries in a cyber-espionage campaign targeting Ukrainian government institutions back to October 2015. The campaign later used Quasar alongside Sobaken RAT and the custom Vermin backdoor.
JPCERT/CC reported that the open-source remote administration tool originally called xRAT was renamed to Quasar. This marked the start of the malware family being tracked under the Quasar name.
Zscaler reported that Thailand Pass published an advisory on its official website warning about a malicious campaign impersonating its travel registration service. The campaign delivered AsyncRAT through spoofed Thailand Pass lures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcezscaler.com
Open sourceresearch.openanalysis.net
Open sourcelabs.k7computing.com
Open sourceblogs.jpcert.or.jp
Open sourcewelivesecurity.com
Open sourcejsac.jpcert.or.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.