Pulsar RAT is a Windows-focused .NET remote access trojan associated with multi-stage, stealth-oriented intrusion chains and recurring supply-chain and loader-based distribution. It has been described as an open-source RAT and as a derivative of Quasar RAT, with modular functionality centered on remote control, credential theft, surveillance, and data exfiltration. Observed campaigns commonly execute Pulsar largely in memory using PowerShell loaders, Donut-generated shellcode, reflective loading, and process injection into legitimate Windows processes to reduce disk artifacts and hinder detection.
Documented Pulsar RAT capabilities include remote command execution, file and system interaction, browser credential theft, browser profile theft, keylogging, screen capture, webcam capture, audio capture, and theft of application secrets and other sensitive user data. Some samples also implement cryptocurrency clipboard hijacking and anti-analysis logic, including anti-VM and anti-debugging checks. Persistence has been observed through per-user Run key mechanisms and scheduled tasks, and some delivery chains include UAC-bypass behavior and watchdog-style reinfection or process migration to maintain execution.
Pulsar RAT has been delivered through several distinct infection vectors. Reported chains include malicious npm packages targeting developers, including typosquatted and heavily obfuscated packages that use steganography to extract hidden payloads from PNG images; staged delivery via DonutLoader; and Windows Installer packages that launch obfuscated DLL loaders through custom actions. In one analyzed MSI-based campaign, the loader decoded shellcode from GUID-formatted data, disabled AMSI, ETW, and Windows Lockdown Policy checks, then reflectively loaded the Pulsar RAT payload in memory. Broader reporting also links Pulsar RAT to fake installers and multi-payload criminal operations.
Targeting is strongest and most consistently supported for Windows systems, including developer environments and general user endpoints. Reported operator objectives include credential theft, theft of browser and wallet data, surveillance, and full remote control of compromised hosts. Exfiltration has been observed through attacker-controlled infrastructure as well as common online services used to blend malicious traffic with normal activity. Pulsar RAT appears in financially motivated and opportunistic campaigns rather than being tied at high confidence to a single well-established threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
40 distinct techniques documented for this family, organized by ATT&CK tactic.
The decoded PowerShell script functions as an advanced in-memory loader... launches it using a hidden PowerShell instance with execution policy bypass enabled
GUID-encoded shellcode — 973 KB of x64 shellcode stored as 60,820 Windows GUIDs in the PE .rdata section, evading signature-based detection
“extracts an embedded Base64-encoded PowerShell payload…” and “contains an encrypted byte array that is decrypted at runtime using a bitwise XOR routine”
Exports Name cfgmgr.dll (Windows Configuration Manager — DLL hijack masquerade)
...injects the decrypted shellcode into a legitimate process and spawns a remote thread to begin execution.
“Defense Evasion T1070.004 Indicator Removal: File Deletion” and “writes it temporarily to disk… and then deletes the script.”
T1140 Deobfuscate/Decode Files GUID-to-bytes decoding at runtime
Anti-VM CheckForVMwareAndVirtualBox , VMware/VirtualBox/QEMU/Parallels strings
Category Evidence Screen capture SharpDX , SharpDX.Direct3D11 , SharpDX.DXGI , SharpDX.D3DCompiler
Clipboard hijack : Monitors clipboard continuously; replaces any recognized crypto address with attacker's address
Category Evidence Audio NAudio.Core , NAudio.Wasapi , Error stopping audio
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A payload family explicitly described as deployed by DonutLoader.
A RAT family identified as one of the payloads hosted and delivered by the operator in this campaign cluster.
An open-source .NET remote access trojan delivered by haunt.msi. It supports keylogging, screen capture/streaming, webcam and audio capture, browser credential theft, browser profile cloning, remote chat, process injection, persistence, anti-VM/anti-debug checks, IP geolocation, and cryptocurrency clipboard hijacking. The sample uses a custom loader with GUID-encoded shellcode, in-memory CLR hosting, and AMSI/ETW/WLDP bypasses before reflectively loading the Pulsar RAT payload.
Open-source .NET remote access trojan delivered by the malicious npm package buildrunner-dev.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.