Quasar RAT is an open-source .NET remote access trojan and backdoor derived from xRAT that has been publicly available since 2015. It is widely abused in criminal and espionage operations because it provides full remote administration of compromised Windows systems while remaining easy to customize and redeploy. Quasar RAT has appeared both as a standalone implant and as a downstream payload delivered by loaders, malicious repositories, fake software projects, and phishing-driven intrusion chains.
Quasar RAT supports a broad set of post-compromise capabilities typical of commodity remote access malware. Documented functions include remote command execution, process and system management, registry editing, user and account enumeration, webcam access, hidden-window execution, and the ability to hide files by setting hidden attributes. Reporting also places Quasar-family implants in intrusion chains that use in-memory loading, AMSI tampering, process injection, and persistence mechanisms such as services or scheduled tasks, although some of those behaviors may be implemented by surrounding loaders rather than the core open-source client itself.
The malware is frequently delivered through social engineering rather than exploit-led intrusion. Observed delivery patterns include phishing attachments, fake tax or government lures, trojanized developer packages, malicious GitHub repositories, deceptive software utilities, game cheats, and cryptocurrency or blockchain-themed tooling. Quasar has also been deployed by multi-stage loaders and DLL sideloading chains that use legitimate signed executables as launch points.
Quasar RAT is used by a diverse set of actors. It has been associated with commodity cybercrime, financially motivated intrusion sets, and state-linked espionage activity. Reporting has tied customized or operational use of Quasar to groups including APT10/menuPass, Bluebottle/OPERA1ER, and North Korea-linked Konni activity, while other campaigns have used Quasar alongside families such as AsyncRAT, Remcos, Vidar, NetWire, and Gh0st-derived implants. Because Quasar is open source and broadly available, its presence alone is not attribution-quality evidence.
Targeting is correspondingly broad. Quasar has been observed against governments, managed service providers, financial institutions, developers and DevOps personnel, blockchain and cryptocurrency users, and victims reached through regional phishing campaigns such as tax-themed operations in India and social-engineering campaigns in South Korea. In 2026, reporting highlighted a shift in some Quasar-related activity toward theft of developer ecosystem credentials, including access associated with source-code and package-management workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat Details and IOCs Malware: ... Quasar RAT, QuasarRAT ...
The vulnerability, assigned the CVE identifier CVE-2024-4577... an argument injection vulnerability in PHP affecting Windows-based systems running in CGI mode
17 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
That same reporting identified new or expanded tooling, including HAYMAKER, SNUGRIDE, BUGJUICE, SOGU, and customized QUASARRAT.
01/2017: Downeks and Quasar RAT Used in Recent Targeted Attacks Against Governments – Unit42
Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.
Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
Quasar RAT (Trojan.Quasar): Commodity RAT that can be used to steal passwords and execute commands on an infected computer.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
The infection begins on fraudulent websites that copy the look of the Indian Income Tax Department, each using an “/incometax” path and a fabricated compliance notice.
Socket has published research findings describing a Go module that posed as a DNS and subdomain scanner while acting as a first-stage Windows malware loader.
Phishing emails with ZIP attachments containing .wsf scripts or OneNote (.hta) files that trigger batch (.bat) execution
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com.
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com, decodes it with certutil, and runs the result with execution-policy bypass.
a Quasar or AsyncRAT family .NET implant that patches the Antimalware Scan Interface before loading
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
The chain finishes by injecting two payloads into svchost.exe processes across every active user session
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
Socket describes the decoded script as a multi-layer loader using Base64 encoding and XOR decryption.
The malware then fetches a file from its infrastructure that looks like an ordinary JPEG image but actually hides multiple encrypted payloads appended after the picture data.
The chain finishes by injecting two payloads into svchost.exe processes across every active user session
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com, decodes it with certutil, and runs the result... Socket describes the decoded script as a multi-layer loader using Base64 encoding and XOR decryption.
The loader extracts it into a directory named to resemble a legitimate Microsoft Photos install and launches Microsoft.exe from that path with a hidden window.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The payload chain... communicates with Telegram or other public web services.
Rather than hardcoding a payload URL, the resolver retrieves text from public platforms, searches it for the marker string 'LastW,' then decrypts the trailing blob with a hardcoded key to recover the actual download location. Primary dead drops include Pastebin and a paste service called Rlim, with fallbacks across YouTube, Instagram, Telegram, Google Docs, and GitCode.
429 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
187 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source .NET RAT with client-server architecture used for remote access and credential theft, including developer and CI/CD secrets in newer campaigns.
RAT-family payload identified in decoded stages of the campaign.
Remote access trojan-style payload family associated with downstream activity in the campaign.
Mentioned as a possible family identification for the .NET implant alongside AsyncRAT; it is not conclusively identified as the deployed payload in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.