QuasarRAT
MITRE ATT&CK: S0262 View on attack.mitre.org
Aliases: xRAT, QuasarRAT
- First seen
- 2014-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 6817 (3577 malicious)
- Last IoC activity
- 2026-09-02 04:25:19
- Profile updated
- 2026-07-07 12:48:02
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services education-and-nonprofits
Context
QuasarRAT is an open-source, remote access tool that has been publicly available on GitHub since at least 2014. QuasarRAT is developed in the C# language.
Recent IoC activity
3,577 malicious indicators in Maltiverse are attributed to QuasarRAT (S0262). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | casino-within.at.ply.gg | 2026-09-03 | 2 |
| IP address | 89.163.135.20 | 2026-09-03 | 6 |
| IP address | 3.141.210.37 | 2026-09-03 | 6 |
| IP address | 3.141.177.1 | 2026-09-03 | 6 |
| hostname | pytr.ydns.eu | 2026-09-03 | 1 |
| hostname | esskaybeauty.in | 2026-09-03 | 1 |
| hostname | mahamayajyotishkaryalaya.in | 2026-09-03 | 1 |
| hostname | choose-inserted.gl.at.ply.gg | 2026-09-03 | 1 |
| hostname | imjustdoingmyjob.ddns.net | 2026-09-03 | 1 |
| hostname | tracker.colatv88xb.cc | 2026-09-03 | 2 |
| hostname | branleet.duckdns.org | 2026-09-03 | 1 |
| hostname | 57c42474b0ea.ofalias.net | 2026-09-03 | 1 |
| hostname | the.networkguru.com | 2026-09-03 | 1 |
| hostname | localpc.ddns.net | 2026-09-03 | 1 |
| hostname | throbbing-mountain-09011.pktriot.net | 2026-09-03 | 1 |
| hostname | blackid-30073.portmap.host | 2026-09-03 | 1 |
| hostname | hqnq.sa.com | 2026-09-03 | 1 |
| hostname | short-returning.gl.at.ply.gg | 2026-09-03 | 1 |
| hostname | songs-acid.gl.at.ply.gg | 2026-09-03 | 1 |
| hostname | xcorpitx.ddns.net | 2026-09-03 | 1 |
Detection coverage
- 3 YARA rules
- 474 Sigma rules
Malware & tools used
- Remote Desktop Protocol (attack-pattern)
- Keylogging (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Hidden Window (attack-pattern)
- System Information Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Location Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Data from Local System (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Credentials In Files (attack-pattern)
- Windows Command Shell (attack-pattern)
- Proxy (attack-pattern)
- Non-Standard Port (attack-pattern)
- Code Signing (attack-pattern)
- Application Window Discovery (attack-pattern)
- Scheduled Task (attack-pattern)
- Video Capture (attack-pattern)
Used by threat actors
- Kimsuky (threat-actor)
- Gorgon Group (threat-actor)
- APT-C-36 (threat-actor)
- Patchwork (threat-actor)
- LazyScripter (threat-actor)
- menuPass (threat-actor)
- Kimsuky (threat-actor)
- BackdoorDiplomacy (threat-actor)
Detection rules
- CAPE_Quasarrat (yara-rule)
- CAPE_Quasarrat_Kingrat (yara-rule)
- SEKOIA_Implant_Win_Quasarrat (yara-rule)
Related threat objects
- Quasar RAT (malware)
Reports & references
- volexity.com — Patchwork Apt Group Targets Us Think Tanks (report)
- Trend Micro — Tech Brief Untangling The Patchwork Cyberespionage Group (report)
- Kaspersky — 101519 (report)
- MITRE ATT&CK — S0262 (report)
- github.com — Quasarrat (report)