{
  "family": "quasar",
  "sample_count": 148,
  "category": "trojan",
  "description": "<h3>Executive Summary</h3>\nQuasar RAT is a powerful, open-source Remote Access Trojan (RAT) coded in C#. While originally developed and marketed as a legitimate remote administration tool, its robust feature set, high stability, and public availability on GitHub have made it a staple in the arsenals of cybercriminals and Advanced Persistent Threat (APT) groups. It is utilized post-compromise to maintain deep, interactive control over victim machines, facilitate lateral movement, and exfiltrate sensitive data.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nQuasar is typically deployed as a secondary payload. Threat actors distribute it via malicious email attachments (often weaponized Office documents), fake software installers, or drop it manually after successfully exploiting a vulnerable internet-facing service.\n\nOnce active, it provides the attacker with total system control:\n<ul>\n<li><strong>Extensive Surveillance Capabilities:</strong> The RAT includes built-in modules for real-time keylogging, remote desktop (RDP) viewing, webcam and microphone capture, and password recovery from major web browsers and FTP clients.</li>\n<li><strong>File and System Management:</strong> Attackers have full file system access (upload, download, execute, delete), can interact with the command prompt and PowerShell, and can manipulate running processes and registry keys.</li>\n<li><strong>Evasion and Persistence:</strong> Quasar client builds are highly customizable. Attackers routinely use crypters/packers to obfuscate the binary. It establishes persistence via Scheduled Tasks or Registry `Run` keys, and communicates with the Command and Control (C2) server using TLS-encrypted TCP connections, making network detection difficult.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nA Quasar detection is a critical incident indicating a total compromise of the affected endpoint. The attacker has interactive, human-driven access to the machine and can steal any data present, deploy ransomware, or pivot to attack other internal servers.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Immediate Network Isolation:</strong> Sever the machine's network connection instantly to terminate the attacker's interactive session and halt any ongoing data exfiltration.</li>\n<li><strong>Hunt for Lateral Movement:</strong> Because Quasar is often used as a beachhead, incident responders must assume the attacker has attempted to move laterally. EDR and Active Directory logs must be scrutinized for compromised credentials and unauthorized access to other internal hosts.</li>\n<li><strong>Total Re-imaging and Credential Rotation:</strong> The machine cannot be trusted and must be wiped to bare metal. All credentials (user, service accounts) that were exposed to or logged into the compromised machine must be immediately reset.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "RAT.Quasar",
    "Backdoor.MSIL.Quasar",
    "Win32/QuasarRAT"
  ],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "Is QuasarRAT malware?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "QuasarRAT is an open-source remote-administration tool (publicly on GitHub since at least 2014) that is frequently abused as a remote access trojan."
      }
    },
    {
      "@type": "Question",
      "name": "What language is QuasarRAT written in?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It is developed in C#."
      }
    },
    {
      "@type": "Question",
      "name": "What can QuasarRAT do when abused?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Provide remote control, keylogging, credential theft, and file access on a compromised system."
      }
    },
    {
      "@type": "Question",
      "name": "What is xRAT?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "xRAT is an alias associated with the QuasarRAT project."
      }
    },
    {
      "@type": "Question",
      "name": "How does abused QuasarRAT reach victims?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Typically through phishing and malicious downloads, as with other RATs."
      }
    },
    {
      "@type": "Question",
      "name": "Why is an open-source tool a security concern?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Because the code is freely available, many actors can compile and customize their own builds, making variants common and varied."
      }
    },
    {
      "@type": "Question",
      "name": "Where is the authoritative reference?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "MITRE ATT&CK's QuasarRAT entry (S0262), linked on this page."
      }
    }
  ],
  "faq_count": 7,
  "mitre_attack": [
    "T1071.001",
    "T1056.001",
    "T1055"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-02T07:47:42Z",
  "sources": [
    {
      "name": "MITRE ATT&CK: QuasarRAT (S0262)",
      "url": "https://attack.mitre.org/software/S0262"
    }
  ],
  "mitre_url": "https://attack.mitre.org/software/S0262",
  "type": "Remote Access Trojan (RAT)",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}