QRat
Aliases: Quaverse RAT
- First seen
- 2015-05-01 00:00:00
- Malware type
- rat, keylogger, screen-capture, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:36:18
- Profile updated
- 2026-07-07 14:32:23
Targeted industries: technology-and-telecommunications financial-services
Context
QRat, also known as Quaverse RAT, was introduced in May 2015 as undetectable (because of multiple layers of obfuscation). It offers the usual functionality (password dumper, file browser, keylogger, screen shots/streaming, ...), and it comes as a SaaS. For additional historical context, please see jar.qarallax.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Jar.Qrat (report)
- digitrustgroup.com — Java Rat Qrat (report)
- trustwave.com — Quaverse Rat Remote Access As A Service (report)
- trustwave.com — Updated Qnode Rat Downloader Distributed As Trump Video Scandal (report)
- trustwave.com — Rats And Spam The Nodejs Qrat (report)