Malware

Quasar RAT

Also known as: CinaRAT · QuasarRAT · Yggdrasil

Quasar RAT is a malware family written in .NET which is used by a variety of attackers. The malware is fully functional and open source, and is often packed to make analysis of the source more difficult.

Indicators of Compromise 37

MITRE ATT&CK TTPs 38

T1055
Process Injection
Defense Evasion
T1055.003
Thread Execution Hijacking
Defense Evasion
T1059.001
PowerShell
Execution
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1071.001
Web Protocols
Command And Control
T1074
Data Staged
Collection
T1078
Valid Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1090
Proxy
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1110
Brute Force
Credential Access
T1112
Modify Registry
Defense Evasion
T1129
Shared Modules
Execution
T1134
Access Token Manipulation
Defense Evasion
T1137
Office Application Startup
Persistence
T1140
Deobfuscate/Decode Files or Information
Defense Evasion
T1176
Browser Extensions
Persistence
T1190
Exploit Public-Facing Application
Initial Access
T1197
BITS Jobs
Defense Evasion
T1203
Exploitation for Client Execution
Execution
T1204.002
Malicious File
Execution
T1210
Exploitation of Remote Services
Lateral Movement
T1211
Exploitation for Defense Evasion
Defense Evasion
T1218
System Binary Proxy Execution
Defense Evasion
T1218.011
Rundll32
Defense Evasion
T1484.001
Group Policy Modification
Defense Evasion
T1497.001
System Checks
Defense Evasion
T1547.001
Registry Run Keys / Startup Folder
Persistence
T1553.005
Mark-of-the-Web Bypass
Defense Evasion
T1566
Phishing
Initial Access
T1570
Lateral Tool Transfer
Lateral Movement
T1571
Non-Standard Port
Command And Control
T1573
Encrypted Channel
Command And Control
T1574.002
DLL Side-Loading
Persistence
T1583
Acquire Infrastructure
Resource Development
T1584
Compromise Infrastructure
Resource Development
T1586
Compromise Accounts
Resource Development
T1595.002
Vulnerability Scanning
Reconnaissance

Source Articles

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
UAT-10147, a Chinese-speaking threat actor, is deploying a new cross-platform backdoor named SPECTRE that targets both Windows and Linux systems. The implant includes advanced capabilities such as process injection, credential theft, anti-analysis routines, and EDR evasion via Bring Your Own Vulnerable Driver (BYOVD) techniques. On Linux, SPECTRE deploys a kernel rootkit called Specter, disguised as 'acpi_pad.ko', which uses ftrace-based hooking to hide processes, modules, and enable UID 0 escalation. The actor also leverages SEO fraud tools like BadIIS and a custom ASHX web handler targeting Vietnamese users, along with multiple backdoors including Meterpreter, Noodle RAT, QuasarRAT, and Gh0stCringe for persistence.
talos ·1w ago
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actor Sable Squirrel has spent nearly $7 million acquiring expired domains to exploit their inherited reputation, traffic, and backlinks for illegal sports streaming, online gambling promotion, and malware distribution. The group operates a dual-purpose infrastructure where re-registered domains serve both as streaming platforms and command-and-control (C2) servers for malware such as Quasar RAT and HiddenTear ransomware. The operation targets users in Asia and Australia through social media and ad networks, using a traffic distribution system to redirect victims while evading detection. Additional scavenger actors like Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel are also abusing expired domains for ad fraud, tech support scams, and traffic resale.
hacker-news ·2w ago
The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions | Datadog Security Labs
MUT-9332 is a threat actor targeting Solidity developers via malicious Visual Studio Code extensions named solaibot, among-eth, and blankebesxstnion. These extensions deliver multi-stage malware that establishes persistence, disables security controls, and exfiltrates cryptocurrency wallet credentials. The campaign uses obfuscated scripts, steganography, and multiple command-and-control domains to evade detection, with infrastructure reuse indicating links to a prior Monero cryptominer campaign.
Datadog Security Labs