Quasar RAT
Aliases: CinaRAT, QuasarRAT, Yggdrasil
- First seen
- 2015-07-01 00:00:00
- Malware type
- rat, keylogger, screen-capture
- Family
- Malware family
- Last IoC activity
- 2026-07-22 02:37:20
- Profile updated
- 2026-07-07 15:46:00
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services healthcare-and-pharmaceutical
Context
Quasar RAT is a malware family written in .NET which is used by a variety of attackers. The malware is fully functional and open source, and is often packed to make analysis of the source more difficult.
Detection coverage
- 5 YARA rules
Used by threat actors
- Kimsuky (threat-actor)
Detection rules
- EMBEERESEARCH_Win_Quasar_Rat_Client (yara-rule)
- SEKOIA_Implant_Win_Quasarrat (yara-rule)
- SIGNATURE_BASE_HKTL_NET_GUID_Cinarat (yara-rule)
- CAPE_Quasarrat (yara-rule)
- CAPE_Quasarrat_Kingrat (yara-rule)
Related threat objects
- QuasarRAT (malware)
Reports & references
- ncsc.gov.uk — Joint%20Report%20On%20Publicly%20Available%20Hacking%20Tools%20%28Ncsc%29 (report)
- secureworks.com — Bronze Riverside (report)
- Trend Micro — Collecting In The Dark Tropic Trooper Targets Transportation And Government Organizations (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- volexity.com — Patchwork Apt Group Targets Us Think Tanks (report)
- secureworks.com — Aluminum Saratoga (report)
- CrowdStrike — Report2021Gtr (report)
- Trend Micro — New Apt Group Earth Berberoka Targets Gambling Websites With Old (report)
- Trend Micro — Earth Berberoka Windows Iocs 2.Txt (report)
- botconf.eu — Botconf2022 40 Lunghihorejsi (report)
- secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
- Broadcom/Symantec — Bluebottle Banks Targeted Africa (report)
- proofpoint.com — Around World 90 Days State Sponsored Actors Try Clickfix (report)
- researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
- cybereason.com — Molerats In The Cloud New Malware Arsenal Abuses Cloud Platforms In Middle East Espionage Campaign (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- Broadcom/Symantec — Cicada Apt10 Japan Espionage (report)
- ironnet.com — China Cyber Attacks The Current Threat Landscape (report)
- intel471.com — Privateloader Malware (report)
- intezer.com — Intezer 2020 Go Malware Round Up (report)
- blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)