QuasarRAT, also known as Quasar, is an open-source, .NET-based remote-access trojan used against Windows systems by cyberespionage groups and financially motivated attackers. It supports remote command execution, remote desktop control, screen capture, keylogging, bidirectional file transfer, and process, file, and registry management. Its credential-collection functionality can recover passwords stored by common FTP clients, and it can communicate with command-and-control servers over TCP.
QuasarRAT has been used by APT10, Patchwork, Gorgon Group, Kimsuky, and TA558. Deployment has also been documented in NGC4020 attacks against an industrial organization. Infection routes include distribution through unauthorized home trading software and deployment after exploitation of exposed services, including PHP CGI on Windows through CVE-2024-4577 and DameWare Mini Remote Control through CVE-2019-3980. Attackers have used batch scripts and built-in Windows utilities to retrieve and launch the RAT.
Observed deployments include scheduled-task persistence attempts, ComputerDefaults execution hijacking for UAC bypass, and encrypted loader chains that execute the .NET payload in memory. QuasarRAT samples have also been packed with Themida and signed using stolen Nvidia code-signing certificates. Its availability and extensive remote-control functionality make it suitable for surveillance, credential theft, data transfer, and maintaining post-compromise access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Для проникновения в инфраструктуру атакующие воспользовались RCE-уязвимостью CVE-2019-3980.
Bitdefender issued a critical security advisory regarding CVE-2024-4577, a severe argument injection vulnerability in PHP affecting Windows-based systems running in CGI mode. Since our initial advisory, exploitation attempts have been steadily rising. | In this campaign, Quasar was deployed using batch scripts that download the RAT from known command-and-control (C2) servers.
CVE-2023-46604는 오픈 소스 메시징 및 통합 패턴 서버인 Apache ActiveMQ 서버의 원격 코드 실행 취약점이다. 만약 패치되지 않은 Apache ActiveMQ 서버가 외부에 노출되어 있을 경우 공격자는 원격에서 악의적인 명령을 실행하여 해당 시스템을 장악할 수 있다.
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
In this blog post, I’ll be diving into the technical details of the WinRAR vulnerability, identified as CVE-2025-8088. This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw. | Quasar RAT The RAR archive contains text files and an Alternate Data Stream (ADS) linked to a Quasar RAT executable.
Researchers observed attackers leveraging Zerologon, or CVE-2020-1472, a Microsoft zero-day elevation-of-privilege vulnerability first disclosed and patched on Aug. 11. The flaw—which stems from the Netlogon Remote Protocol available on Windows domain controllers–allows attackers to spoof a domain controller account and then use it to steal domain credentials, take over the domain and completely compromise all Active Directory identity services. | Attackers also installed the QuasarRAT open-source backdoor and novel Backdoor.Hartip tool to continue surveillance on victims’ systems.
These attacks use dcRAT and QuasarRAT for Windows delivered via malicious documents exploiting CVE-2017-11882 — a memory corruption vulnerability in Microsoft Office... A typical infection would consist of a malicious document, such as an RTF file exploiting CVE-2017-11882, a stack overflow vulnerability that enables arbitrary code execution on a vulnerable version of Microsoft Office. | The attack phase consists of deploying RAT payloads, such as DcRAT and QuasarRAT, to the victim’s endpoint.
Both RTFs exploited CVE-2012-0158 and acted as downloaders to ultimately deliver the QuasarRAT malware family.
Among these tricks are using right-to-left override to obscure the attachments’ real extension, email attachments disguised as RAR self-extracting archives, and a combination of a specially crafted Word document carrying a CVE-2017-0199 exploit. | We have detected three different strains of .NET malware in these campaigns: Quasar RAT, Sobaken RAT, and a custom-made RAT called Vermin.
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Threat Details and IOCs Malware: ... Quasar RAT, QuasarRAT ...
31 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Patchwork has obtained and used open-source tools such as QuasarRAT.
Patchwork has obtained and used open-source tools such as QuasarRAT.
연결의 지속성 확보를 위해서 RDP 접속용 계정 생성, RDP Wrapper, Quasar RAT, Ammy RAT, AnyDesk, TeamViewer 등 원격 관리 프로그램 추가 설치.
“We also found traces of a Themida-packed version of Quasar, a malware family we did not see this Lazarus subgroup use before.”
APT41 and APT36 have both employed NjRAT, while APT10 has used QuasarRAT.
“Вторая нагрузка ... это был файл вредоносного ПО QuasarRAT ... который атакующие закрепили с помощью создания задачи в планировщике.”
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure.
The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale.
Using the secondary batch script to silently execute Quasar RAT and establish persistence using a deceptive scheduled task named "Google Chrome Start"
In one case, the threat actor is said to have successfully exploited a website and collected information about the victim host using Linux commands.
File name back.bat Alternate name for the main Windows deployment script File name bai.bat Secondary batch script used for backdoor execution and persistence File name user.bat Script used to create a privileged local account
This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw.
establish persistence using a deceptive scheduled task named "Google Chrome Start"
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
часть инфраструктуры Sable Squirrel используется для работы малвари: к доменам хак-группы обращались более 31 000 образцов вредоносов... некоторые сайты одновременно показывали посетителям спортивные трансляции и работали в качестве управляющих серверов для малвари.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
1,276 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source remote-access trojan with remote-control, keylogging, account-information collection, and remote-desktop capabilities, enabling theft of user information and real-time control of infected systems.
Mentioned only as a comparative RAT family, not as malware deployed by this campaign.
Mentioned only as a family resemblance during analysis; the final payload is assessed as VenomRAT rather than Quasar.
Mentioned only as a family resembling the recovered payload’s namespace layout; it was not identified as the final payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.