QuasarRAT

MITRE ATT&CK: S0262 View on attack.mitre.org

Aliases: xRAT, QuasarRAT

First seen
2014-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
6817 (3577 malicious)
Last IoC activity
2026-09-02 04:25:19
Profile updated
2026-07-07 12:48:02

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services education-and-nonprofits

Context

QuasarRAT is an open-source, remote access tool that has been publicly available on GitHub since at least 2014. QuasarRAT is developed in the C# language.

Recent IoC activity

3,577 malicious indicators in Maltiverse are attributed to QuasarRAT (S0262). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname casino-within.at.ply.gg 2026-09-03 2
IP address 89.163.135.20 2026-09-03 6
IP address 3.141.210.37 2026-09-03 6
IP address 3.141.177.1 2026-09-03 6
hostname pytr.ydns.eu 2026-09-03 1
hostname esskaybeauty.in 2026-09-03 1
hostname mahamayajyotishkaryalaya.in 2026-09-03 1
hostname choose-inserted.gl.at.ply.gg 2026-09-03 1
hostname imjustdoingmyjob.ddns.net 2026-09-03 1
hostname tracker.colatv88xb.cc 2026-09-03 2
hostname branleet.duckdns.org 2026-09-03 1
hostname 57c42474b0ea.ofalias.net 2026-09-03 1
hostname the.networkguru.com 2026-09-03 1
hostname localpc.ddns.net 2026-09-03 1
hostname throbbing-mountain-09011.pktriot.net 2026-09-03 1
hostname blackid-30073.portmap.host 2026-09-03 1
hostname hqnq.sa.com 2026-09-03 1
hostname short-returning.gl.at.ply.gg 2026-09-03 1
hostname songs-acid.gl.at.ply.gg 2026-09-03 1
hostname xcorpitx.ddns.net 2026-09-03 1

Detection coverage

  • 3 YARA rules
  • 474 Sigma rules

Malware & tools used

  • Remote Desktop Protocol (attack-pattern)
  • Keylogging (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Hidden Window (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Modify Registry (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Data from Local System (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Proxy (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Code Signing (attack-pattern)
  • Application Window Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Video Capture (attack-pattern)

Used by threat actors

Detection rules

  • CAPE_Quasarrat (yara-rule)
  • CAPE_Quasarrat_Kingrat (yara-rule)
  • SEKOIA_Implant_Win_Quasarrat (yara-rule)

Related threat objects

Reports & references

  • volexity.com — Patchwork Apt Group Targets Us Think Tanks (report)
  • Trend Micro — Tech Brief Untangling The Patchwork Cyberespionage Group (report)
  • Kaspersky — 101519 (report)
  • MITRE ATT&CK — S0262 (report)
  • github.com — Quasarrat (report)

External references