Quasar RAT

Aliases: CinaRAT, QuasarRAT, Yggdrasil

First seen
2015-07-01 00:00:00
Malware type
rat, keylogger, screen-capture
Family
Malware family
Last IoC activity
2026-07-22 02:37:20
Profile updated
2026-07-07 15:46:00

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services healthcare-and-pharmaceutical

Context

Quasar RAT is a malware family written in .NET which is used by a variety of attackers. The malware is fully functional and open source, and is often packed to make analysis of the source more difficult.

Detection coverage

  • 5 YARA rules

Used by threat actors

Detection rules

  • EMBEERESEARCH_Win_Quasar_Rat_Client (yara-rule)
  • SEKOIA_Implant_Win_Quasarrat (yara-rule)
  • SIGNATURE_BASE_HKTL_NET_GUID_Cinarat (yara-rule)
  • CAPE_Quasarrat (yara-rule)
  • CAPE_Quasarrat_Kingrat (yara-rule)

Related threat objects

Reports & references

  • ncsc.gov.uk — Joint%20Report%20On%20Publicly%20Available%20Hacking%20Tools%20%28Ncsc%29 (report)
  • secureworks.com — Bronze Riverside (report)
  • Trend Micro — Collecting In The Dark Tropic Trooper Targets Transportation And Government Organizations (report)
  • Broadcom/Symantec — Elfin Apt33 Espionage (report)
  • volexity.com — Patchwork Apt Group Targets Us Think Tanks (report)
  • secureworks.com — Aluminum Saratoga (report)
  • CrowdStrike — Report2021Gtr (report)
  • Trend Micro — New Apt Group Earth Berberoka Targets Gambling Websites With Old (report)
  • Trend Micro — Earth Berberoka Windows Iocs 2.Txt (report)
  • botconf.eu — Botconf2022 40 Lunghihorejsi (report)
  • secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
  • Broadcom/Symantec — Bluebottle Banks Targeted Africa (report)
  • proofpoint.com — Around World 90 Days State Sponsored Actors Try Clickfix (report)
  • researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
  • cybereason.com — Molerats In The Cloud New Malware Arsenal Abuses Cloud Platforms In Middle East Espionage Campaign (report)
  • Broadcom/Symantec — Elfin Apt33 Espionage (report)
  • Broadcom/Symantec — Cicada Apt10 Japan Espionage (report)
  • ironnet.com — China Cyber Attacks The Current Threat Landscape (report)
  • intel471.com — Privateloader Malware (report)
  • intezer.com — Intezer 2020 Go Malware Round Up (report)
  • blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • spamhaus.org — Botnet Threat Update July To December 2025 (report)
  • info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)

External references