Malware
Quasar RAT
Also known as: CinaRAT · QuasarRAT · Yggdrasil
Quasar RAT is a malware family written in .NET which is used by a variety of attackers. The malware is fully functional and open source, and is often packed to make analysis of the source more difficult.
Indicators of Compromise 37
Domain 6789x[.]site Domain archive[.]org Domain begalinokotobananinotrippitroppacrocofanclub[.]su Domain cel-robox[.]com Domain healthymagination[.]com Domain krogeralbertsons[.]com Domain m-vn[.]ws Domain maxfactor-international[.]com Domain myaunet[.]su Domain paste[.]ee Domain rezilion[.]com Domain snsystems[.]com Domain solidity[.]bot Domain vn[.]xyz Filename 1.txt Filename 2.txt Filename 3.txt Filename C:\Windows\System32\drivers\etc\hosts:cache Filename Launch.exe Filename a.txt Filename a.vbs Filename acpi_pad.ko Filename demo.pdb Filename extension.zip Filename myau.exe Filename myaunet.exe Filename service.pdb Filename wmam.exe GitHub Repo widestring-1.2.1 SHA-256 209fb5bb2440ffe1a631dfe3b574229105a33c5153eded023cc77d8e8f81d1de SHA-256 a1eadd41327bd8736e275627d3953944fe7089c032d72a3e429ff18ad0958ada SHA-256 c3684164933c3f54d5b0b242a8a906a85d633de479079a820bb804c0f73c0f58 SHA-256 c5c0228a1e0ba2bb748219325f66acf17078a26165b45728d8e98150377aa068 SHA-256 ce72b79e324371134db762fe70b8b1789af899d7217461bc3658a6bd84743eb6 SHA-256 e0ca66c1a9a68b319b24a7c6b8fdca219dffd802dd4de2d59f602c4d90f40d6c SHA-256 e19d5d8f941b9a98fbb3b65e1e6077fa00d97529e351e455297b0204ec07e9ed Registry User index.crates.io-1949cf8c6b5b557f
MITRE ATT&CK TTPs 38
T1055 T1055.003 T1059.001 T1068 T1071.001 T1074 T1078 T1082 T1090 T1105 T1110 T1112 T1129 T1134 T1137 T1140 T1176 T1190 T1197 T1203 T1204.002 T1210 T1211 T1218 T1218.011 T1484.001 T1497.001 T1547.001 T1553.005 T1566 T1570 T1571 T1573 T1574.002 T1583 T1584 T1586 T1595.002
Process Injection
Defense Evasion
Thread Execution Hijacking
Defense Evasion
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Web Protocols
Command And Control
Data Staged
Collection
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Modify Registry
Defense Evasion
Shared Modules
Execution
Access Token Manipulation
Defense Evasion
Office Application Startup
Persistence
Deobfuscate/Decode Files or Information
Defense Evasion
Browser Extensions
Persistence
Exploit Public-Facing Application
Initial Access
BITS Jobs
Defense Evasion
Exploitation for Client Execution
Execution
Malicious File
Execution
Exploitation of Remote Services
Lateral Movement
Exploitation for Defense Evasion
Defense Evasion
System Binary Proxy Execution
Defense Evasion
Rundll32
Defense Evasion
Group Policy Modification
Defense Evasion
System Checks
Defense Evasion
Registry Run Keys / Startup Folder
Persistence
Mark-of-the-Web Bypass
Defense Evasion
Phishing
Initial Access
Lateral Tool Transfer
Lateral Movement
Non-Standard Port
Command And Control
Encrypted Channel
Command And Control
DLL Side-Loading
Persistence
Acquire Infrastructure
Resource Development
Compromise Infrastructure
Resource Development
Compromise Accounts
Resource Development
Vulnerability Scanning
Reconnaissance
Source Articles
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
UAT-10147, a Chinese-speaking threat actor, is deploying a new cross-platform backdoor named SPECTRE that targets both Windows and Linux systems. The implant includes advanced capabilities such as process injection, credential theft, anti-analysis routines, and EDR evasion via Bring Your Own Vulnerable Driver (BYOVD) techniques. On Linux, SPECTRE deploys a kernel rootkit called Specter, disguised as 'acpi_pad.ko', which uses ftrace-based hooking to hide processes, modules, and enable UID 0 escalation. The actor also leverages SEO fraud tools like BadIIS and a custom ASHX web handler targeting Vietnamese users, along with multiple backdoors including Meterpreter, Noodle RAT, QuasarRAT, and Gh0stCringe for persistence.
talos ·1w ago
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actor Sable Squirrel has spent nearly $7 million acquiring expired domains to exploit their inherited reputation, traffic, and backlinks for illegal sports streaming, online gambling promotion, and malware distribution. The group operates a dual-purpose infrastructure where re-registered domains serve both as streaming platforms and command-and-control (C2) servers for malware such as Quasar RAT and HiddenTear ransomware. The operation targets users in Asia and Australia through social media and ad networks, using a traffic distribution system to redirect victims while evading detection. Additional scavenger actors like Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel are also abusing expired domains for ad fraud, tech support scams, and traffic resale.
hacker-news ·2w ago
The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions | Datadog Security Labs
MUT-9332 is a threat actor targeting Solidity developers via malicious Visual Studio Code extensions named solaibot, among-eth, and blankebesxstnion. These extensions deliver multi-stage malware that establishes persistence, disables security controls, and exfiltrates cryptocurrency wallet credentials. The campaign uses obfuscated scripts, steganography, and multiple command-and-control domains to evade detection, with infrastructure reuse indicating links to a prior Monero cryptominer campaign.
Datadog Security Labs