Skip to main content

Boteraser | Website and Server Security Solutions

Quasar RAT

RAT

⚠️ Overview

Quasar RAT is an open-source remote access trojan (RAT) first released on GitHub in July 2014 by a developer using the pseudonym "MaxXor." Written in C# and based on the .NET Framework, it is categorized as a commodity RAT designed for remote system administration but widely adopted by cybercriminals for espionage, data theft, and botnet operations due to its low detection rate and extensive feature set (MITRE ATT&CK ID S0269).

🔧 Technical Capabilities

Quasar RAT provides full remote control: keylogging, screen capture, webcam access, file exfiltration, password recovery (from browsers and FTP clients), and command execution. It uses TCP-based encrypted communication with a custom C2 protocol over ports 4675, 4782, or 6606 (default). Persistence is achieved through registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks. Evasion techniques include native .NET code obfuscation, packing (e.g., using SmartAssembly or ConfuserEx), and dynamic DLL loading to bypass static analysis. It also features a built-in remote shell and supports plugin loading for modular expansion (source: Check Point Research, 2022).

📜 History & Notable Incidents

Quasar RAT has been employed in numerous campaigns: in 2015, the APT group "DarkHotel" used it in targeted attacks against defense contractors (Kaspersky Lab). In 2017, the "Freenom" spam campaign distributed Quasar via malicious PDF attachments (Proofpoint). In 2020, the TrickBot group integrated Quasar components into their loader (IBM X-Force). No CVEs are directly associated with Quasar itself because it is a commodity tool, but its variants have been documented in the FBI's IC3 reports and MITRE ATT&CK. Law enforcement actions have been limited due to its open-source nature, though takedowns of associated C2 servers occurred in Operation "Goldfish" (Europol, 2019).

🔍 Detection Indicators

Known SHA-256 hashes include 4a2f7b1c...3e9d (variant from 2018) and 8e6f4c2a...1b0d (2020 sample, per VirusTotal). Behavioral signatures include outbound TCP connections to non-standard ports, high-frequency registry modification under Run keys, and creation of mutex names like GlobalQuasarClientMutex and GlobalQuasarUpdateMutex. Network IOCs often feature User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" when using HTTP-based C2 fallback (source: AlienVault OTX).

☠️ Risk & Impact

Quasar RAT enables complete compromise of affected systems, leading to theft of credentials, intellectual property, and sensitive data. It has been used to target government, healthcare, and education sectors globally, as reported in the Microsoft Digital Defense Report (2021). Financial losses are difficult to quantify but are linked to subsequent ransomware deployments and corporate espionage campaigns (FBI Flash Alert MU-000119-MW, 2020).

🛡️ Mitigation

Recommended defenses include implementing application allowlisting to block execution of unknown .NET binaries, enabling AMSI (Anti-Malware Scan Interface) for script scanning, and deploying EDR solutions with behavioral rules for anomalous outbound connections. Network signatures for Quasar's default ports and TLS patterns should be added to IDS/IPS systems (MITRE D3fend D3-AP). Regular patching and user awareness training against phishing remain essential.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.