Skip to main content
Mallory
MalwareUsed by 18 actorsExploits 2 CVEs

QuasarRAT

Also known asquasar

QuasarRAT is an open-source .NET remote access trojan (RAT), also referred to as Quasar or Quasar RAT. It is commodity malware that has been used by a wide range of actors and also customized by advanced threat groups. Reported users include Gorgon Group, APT33/Elfin, and APT10/MenuPass; APT10 used customized QuasarRAT versions 1.3.4.0, 2.0.0.0, and 2.0.0.1 that were not available on the public GitHub page, and FireEye reported the 2.0 variants required a dropper to decipher and launch an AES-encrypted payload. The malware has also been observed in Nigerian BEC operations and is tracked in community C2 infrastructure feeds.

Capabilities directly described in the content include determining the victim host country/location, obtaining passwords from common web browsers, obtaining passwords from common FTP clients, performing remote desktop access, and using WMI commands for system information discovery. QuasarRAT also contains a .NET wrapper DLL for creating and managing scheduled tasks to maintain persistence across reboot. It has been described as capable of stealing passwords and executing commands on an infected computer.

Observed deployment and operational context in the content includes Elfin installing Quasar RAT at appdata\roaming\microsoft\crypto\smss.exe with command-and-control at 217.147.168.123 during a 2018 intrusion against a U.S. organization. The content also notes reporting of a modified Quasar RAT payload that included SharpSploit. QuasarRAT has been digitally signed in some cases, including a sample signed with an AirVPN certificate, and separate reporting noted a Quasar remote access trojan signed with a stolen NVIDIA certificate. The malware is also referenced as one of several open-source malware projects that have inspired derivative families over time.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2025-55182React2Shell

Threat Details and IOCs Malware: ... Quasar RAT, QuasarRAT ...

via f5 communitycommunity.f5.com
CVE-2024-4577PHP-CGI Argument Injection RCE on WindowsExploited in the wild

The vulnerability, assigned the CVE identifier CVE-2024-4577... an argument injection vulnerability in PHP affecting Windows-based systems running in CGI mode

via cloudatg insightscloudatg.com
THREAT ACTORS

Groups observed using it

18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Gorgon Group

Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.

via mitre attack websiteattack.mitre.org
Patchwork

Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.

via mitre attack websiteattack.mitre.org
SilverTerrier

The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.

via bleeping computerbleepingcomputer.com
APT33

Quasar RAT (Trojan.Quasar): Commodity RAT that can be used to steal passwords and execute commands on an infected computer.

via symantec enterprise blogssymantec-enterprise-blogs.security.com
menuPass

QUASARRAT is an open-source RAT... The versions used by APT10 (1.3.4.0, 2.0.0.0, and 2.0.0.1) are not available via the public GitHub page, indicating that APT10 has further customized the open source version.

via web archiveweb.archive.org
Kimsuky

The attack chain, the company explained, initiated a multi-stage sequence that culminated in the deployment of an open-source remote access trojan named Quasar RAT.

via the hacker newsthehackernews.com
TA429

The blog claims that this URL delivered a modified Quasar RAT payload which included the addition of SharpSploit, an opensource post-exploitation tool.

via proofpoint threat insight blogproofpoint.com
DarkCasino

QuasarRAT v1.4.1.0 serves as the primary implant -- a full-featured .NET RAT with credential stealing via browser password databases, keylogging through the Gma.System.MouseKeyHook library, registry manipulation, and file management capabilities. A second variant, QuasarRAT v1.8.8 "Sentinel", was discovered packed with Costura and bundled with six DLLs providing HVNC (Hidden Virtual Network Computing), dedicated keylogging, and browser credential theft modules.

via breakglass intelintel.breakglass.tech
WaterHydra

QuasarRAT v1.4.1.0 serves as the primary implant -- a full-featured .NET RAT with credential stealing via browser password databases, keylogging through the Gma.System.MouseKeyHook library, registry manipulation, and file management capabilities. A second variant, QuasarRAT v1.8.8 "Sentinel", was discovered packed with Costura and bundled with six DLLs providing HVNC (Hidden Virtual Network Computing), dedicated keylogging, and browser credential theft modules.

via breakglass intelintel.breakglass.tech
Transparent Tribe

"Malware: Waizsar RAT, Mobzsar, Amphibeon, MumbaiDown, Quasar RAT"

via crowdstrike bloggo.crowdstrike.com
CTG-5938

Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike

via secureworks threat profilessecureworks.com
APT-C-36

TAG-144 leverages a range of commodity remote access trojans (RATs), including AsyncRAT, REMCOS RAT, DcRAT, njRAT, LimeRAT, QuasarRAT, BitRAT, and a Quasar variant known as BlotchyQuasar.

via recorded future blogrecordedfuture.com
TAG-144

TAG-144 leverages a range of commodity remote access trojans (RATs), including AsyncRAT, REMCOS RAT, DcRAT, njRAT, LimeRAT, QuasarRAT, BitRAT, and a Quasar variant known as BlotchyQuasar.

via recorded future blogrecordedfuture.com
GALLIUM

"Another type of malware that the attackers attempted to use is Quasar RAT."

via palo alto networks unit 42 blogunit42.paloaltonetworks.com
UAC-0050

...застосовано... шкідливих програм: REMCOS RAT, QUASAR RAT, VENOM RAT, REMOTE UTILITIES та LUMMASTEALER.

via cert uacert.gov.ua
Molerats

Downeks makes a POST request to dw.downloadtesting[.]com, resulting in the installation of the Quasar RAT on the victim machine.

via palo alto networks unit 42 blogunit42.paloaltonetworks.com
Red Akodon

...using remote access trojans (RAT) like RemcosRAT, QasarRat, AsyncRAT...; the installation of the RemcosRAT and Quasar Trojans was observed.

via scilabs blogblog.scilabs.mx
aluminum_saratoga

“ALUMINUM SARATOGA uses many openly available tools for its operations, including… QuasarRat…”

via secureworks threat profilessecureworks.com
MITRE ATT&CK

Techniques & procedures

27 distinct techniques documented for this family, organized by ATT&CK tactic.

Reconnaissance

1 technique
T1592Gather Victim Host InformationEvidence1

Volt Typhoon has obtained the victim's system current location.

T1588.002ToolEvidence1

The content repeatedly states that threat actors 'obtained,' 'acquired,' or 'used' publicly available, open-source, legitimate, or modified tools such as Mimikatz, Cobalt Strike, PsExec, Empire, Impacket, and many others.

Execution

4 techniques
T1053.005Scheduled TaskEvidence3

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1059Command and Scripting InterpreterEvidence1
TacticExecution

Baobeilong (宝贝龙/”Baby Dragon”) also maintained a GitHub account that had forked both the Quasar and Trochilus RATs, two open-source tools historically used by STONE PANDA... Falcon Intelligence recently independently conducted detailed analysis of the RedLeaves malware... found it was directly sourced from Trochilus code

T1059.003Windows Command ShellEvidence2
TacticExecution

The content repeatedly describes use of cmd.exe, cmd /c, Windows command shell, and xp_cmdshell to execute commands, run payloads, launch binaries, perform reconnaissance, persistence, cleanup, and ransomware actions. Examples include: 'Sandworm Team used the xp_cmdshell command in MS-SQL', 'APT41 used cmd.exe /c to execute commands on remote machines', and many malware families 'can use cmd.exe to execute commands on a compromised host.' | Many entries explicitly state malware 'can create a reverse shell' or 'launch a remote shell,' including 4H RAT, AuditCred, BLACKCOFFEE, Carbanak, DarkComet, Exaramel for Windows, PlugX, QuasarRAT, and ZxShell.

T1204.002Malicious FileEvidence1
TacticExecution

Therefore, using these stolen certificates, threat actors gain the advantage of making their programs look like legitimate NVIDIA programs and allowing malicious drivers to be loaded by Windows.

Persistence

3 techniques
T1053.005Scheduled TaskEvidence3

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1112Modify RegistryEvidence4

Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.

T1547.001Registry Run Keys / Startup FolderEvidence4

The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, or .lnk files in the Startup folder.

T1053.005Scheduled TaskEvidence3

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1547.001Registry Run Keys / Startup FolderEvidence4

The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, or .lnk files in the Startup folder.

Stealth

3 techniques
T1027Obfuscated Files or InformationEvidence3
TacticStealth

To keep them under the antivirus radar, Nigerian actors techniques use "crypters" - software tools designed to encrypt, obfuscate, and modify malware.

T1036MasqueradingEvidence1
TacticStealth

During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.

T1497.001System ChecksEvidence1

DarkGate queries system locale information during execution. Later versions of DarkGate query GetSystemDefaultLCID for locale information to determine if the malware is executing in Russian-speaking countries.

Defense Impairment

2 techniques
T1112Modify RegistryEvidence4

Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.

T1553.002Code SigningEvidence2

Threat actors are using stolen NVIDIA code signing certificates to sign malware to appear trustworthy and allow malicious drivers to be loaded in Windows. | According to samples uploaded to the VirusTotal malware scanning service, the stolen certificates were used to sign various malware and hacking tools, such as Cobalt Strike beacons, Mimikatz, backdoors, and remote access trojans.

Credential Access

3 techniques
T1056.001KeyloggingEvidence1

T1056.001 Agent Tesla, AsyncRAT, gh0st RAT, Lokibot, njRAT, PlugX, QuasarRAT, Remcos, XWorm

T1555Credentials from Password StoresEvidence3

APT39 has used the Smartftp Password Decryptor tool to decrypt FTP passwords... DarkGate use Nirsoft Network Password Recovery or NetPass tools to steal stored RDP credentials... PoshC2 can decrypt passwords stored in the RDCMan configuration file... Volt Typhoon has attempted to obtain credentials from OpenSSH, realvnc, and PuTTY. | Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI.

T1555.003Credentials from Web BrowsersEvidence2

The content repeatedly describes threat actors and malware stealing usernames, passwords, cookies, session tokens, and other saved credentials from web browsers such as Chrome, Firefox, Internet Explorer, Edge, Opera, Safari, and Yandex.

Discovery

6 techniques
T1016System Network Configuration DiscoveryEvidence1
TacticDiscovery

The content repeatedly describes actors and malware using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, netsh interface show, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, and network adapter/interface details.

T1033System Owner/User DiscoveryEvidence2
TacticDiscovery

The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking admin status, and enumerating user sessions.

T1069Permission Groups DiscoveryEvidence1
TacticDiscovery

Examples include 'TrickBot can identify the user and groups the user belongs to on a compromised host' and multiple entries checking whether the current user is an administrator or has elevated privileges.

T1082System Information DiscoveryEvidence2
TacticDiscovery

The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."

T1087Account DiscoveryEvidence1
TacticDiscovery

Examples include 'Caterpillar WebShell can obtain a list of user accounts from a victim's machine,' 'Woody RAT can retrieve a list of user accounts and usernames,' and 'APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users.'

T1497.001System ChecksEvidence1

DarkGate queries system locale information during execution. Later versions of DarkGate query GetSystemDefaultLCID for locale information to determine if the malware is executing in Russian-speaking countries.

Lateral Movement

1 technique
T1021Remote ServicesEvidence1

The content references repeated use of remote administration and remote execution tools such as PsExec, AnyDesk, Atera, ConnectWise, RemoteUtilities, SimpleHelp, PcShare, VNC, and commodity remote access tools.

Collection

1 technique
T1056.001KeyloggingEvidence1

T1056.001 Agent Tesla, AsyncRAT, gh0st RAT, Lokibot, njRAT, PlugX, QuasarRAT, Remcos, XWorm

T1071Application Layer ProtocolEvidence2

Recorded Future tracks the creation and modification of new malicious infrastructure for a multitude of post-exploitation toolkits, custom malware, and open-source remote access trojans (RATs). We observed over 17,000 unique command-and-control (C2) servers during 2022...

T1071.001Web ProtocolsEvidence1

The debug messages visible in the output show another unusual feature of the malware – the use of HEAD requests

T1105Ingress Tool TransferEvidence3

the attackers became active on the compromised machine and proceeded to download the archiving tool WinRAR... attackers were observed downloading a custom .NET FTP tool... using Quasar RAT to download a second custom AutoIt FTP exfiltration tool known as FastUploader...

T1219Remote Access ToolsEvidence4

4H RAT has the capability to create a remote shell. AuditCred can open a reverse shell on the system to execute commands. PlugX allows actors to spawn a reverse shell on a victim. QuasarRAT can launch a remote shell to execute commands on the victim’s machine.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

Many entries state malware or actors can upload, transfer, send, or exfiltrate files from compromised hosts to command-and-control servers or attacker infrastructure.

Impact

1 technique
T1657Financial TheftEvidence1
TacticImpact

Scammers running business email compromise (BEC) fraud have grown in number, attack more often, and turn to remote access trojans as the preferred malware type to accompany their raids.

INDICATORS OF COMPROMISE

IOCs tracked for this family

331 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
154 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
162 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
15 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app13 days ago
ip.v4●●●●●●●●●●●●View more in app13 days ago
ip.v4●●●●●●●●●●●●View more in app13 days ago
domain●●●●●●●●●●●●View more in app13 days ago
ip.v4●●●●●●●●●●●●View more in app16 days ago
ip.v4●●●●●●●●●●●●View more in app16 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching331

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution18

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping27

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.