QuiteRAT

Aliases: Acres

First seen
2023-01-15 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 14:44:40

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

QuiteRAT is a simple remote access trojan written with the help of Qt libraries. After sending preliminary system information to its C&C server, it expects a response containing either a supported command code or an actual Windows command (like systeminfo or ipconfig with parameters) to execute. It was deployed in a campaign exploiting a ManageEngine ServiceDesk vulnerability (CVE-2022-47966).

Detection coverage

  • 2 YARA rules

Exploited vulnerabilities

  • CVE-2022-47966 (vulnerability)

Detection rules

  • DITEKSHEN_MALWARE_Win_Quiterat (yara-rule)
  • MALPEDIA_Win_Quiterat_Auto (yara-rule)

Reports & references

  • asec.ahnlab.com — 56256 (report)
  • businessinsights.bitdefender.com — Tech Advisory Manageengine Cve 2022 47966 (report)
  • labs.withsecure.com — Withsecure Lazarus No Pineapple Threat Intelligence Report 2023 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Quiterat (report)
  • Cisco Talos — Lazarus Quiterat (report)

External references