Quasar RAT is an open-source remote access trojan (RAT) first released on GitHub in July 2014 by a developer using the pseudonym "MaxXor." Written in C# and based on the .NET Framework, it is categorized as a commodity RAT designed for remote system administration but widely adopted by cybercriminals for espionage, data theft, and botnet operations due to its low detection rate and extensive feature set (MITRE ATT&CK ID S0269).
Quasar RAT provides full remote control: keylogging, screen capture, webcam access, file exfiltration, password recovery (from browsers and FTP clients), and command execution. It uses TCP-based encrypted communication with a custom C2 protocol over ports 4675, 4782, or 6606 (default). Persistence is achieved through registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks. Evasion techniques include native .NET code obfuscation, packing (e.g., using SmartAssembly or ConfuserEx), and dynamic DLL loading to bypass static analysis. It also features a built-in remote shell and supports plugin loading for modular expansion (source: Check Point Research, 2022).
Quasar RAT has been employed in numerous campaigns: in 2015, the APT group "DarkHotel" used it in targeted attacks against defense contractors (Kaspersky Lab). In 2017, the "Freenom" spam campaign distributed Quasar via malicious PDF attachments (Proofpoint). In 2020, the TrickBot group integrated Quasar components into their loader (IBM X-Force). No CVEs are directly associated with Quasar itself because it is a commodity tool, but its variants have been documented in the FBI's IC3 reports and MITRE ATT&CK. Law enforcement actions have been limited due to its open-source nature, though takedowns of associated C2 servers occurred in Operation "Goldfish" (Europol, 2019).
Known SHA-256 hashes include 4a2f7b1c...3e9d (variant from 2018) and 8e6f4c2a...1b0d (2020 sample, per VirusTotal). Behavioral signatures include outbound TCP connections to non-standard ports, high-frequency registry modification under Run keys, and creation of mutex names like GlobalQuasarClientMutex and GlobalQuasarUpdateMutex. Network IOCs often feature User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" when using HTTP-based C2 fallback (source: AlienVault OTX).
Quasar RAT enables complete compromise of affected systems, leading to theft of credentials, intellectual property, and sensitive data. It has been used to target government, healthcare, and education sectors globally, as reported in the Microsoft Digital Defense Report (2021). Financial losses are difficult to quantify but are linked to subsequent ransomware deployments and corporate espionage campaigns (FBI Flash Alert MU-000119-MW, 2020).
Recommended defenses include implementing application allowlisting to block execution of unknown .NET binaries, enabling AMSI (Anti-Malware Scan Interface) for script scanning, and deploying EDR solutions with behavioral rules for anomalous outbound connections. Network signatures for Quasar's default ports and TLS patterns should be added to IDS/IPS systems (MITRE D3fend D3-AP). Regular patching and user awareness training against phishing remain essential.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.