{
  "family": "quasarrat",
  "sample_count": 1,
  "category": "ransomware",
  "description": "<h3>Executive Summary</h3>\nQuasarRAT is a powerful, open-source Remote Access Trojan (RAT) coded in C#. While originally developed and marketed as a legitimate remote administration tool, its robust feature set, high stability, and public availability on GitHub have made it a staple in the arsenals of cybercriminals and Advanced Persistent Threat (APT) groups. It is utilized post-compromise to maintain deep, interactive control over victim machines, facilitate lateral movement, and exfiltrate sensitive data.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nQuasarRAT is typically deployed as a secondary payload. Threat actors distribute it via malicious email attachments (often weaponized Office documents), fake software installers, or drop it manually after successfully exploiting a vulnerable internet-facing service.\n\nOnce active, it provides the attacker with total system control:\n<ul>\n<li><strong>Extensive Surveillance Capabilities:</strong> The RAT includes built-in modules for real-time keylogging, remote desktop (RDP) viewing, webcam and microphone capture, and password recovery from major web browsers and FTP clients.</li>\n<li><strong>File and System Management:</strong> Attackers have full file system access (upload, download, execute, delete), can interact with the command prompt and PowerShell, and can manipulate running processes and registry keys.</li>\n<li><strong>Evasion and Persistence:</strong> QuasarRAT client builds are highly customizable. Attackers routinely use crypters/packers to obfuscate the binary. It establishes persistence via Scheduled Tasks or Registry `Run` keys, and communicates with the Command and Control (C2) server using TLS-encrypted TCP connections, making network detection difficult.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nA QuasarRAT detection is a critical incident indicating a total compromise of the affected endpoint. The attacker has interactive, human-driven access to the machine and can steal any data present, deploy ransomware, or pivot to attack other internal servers.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Immediate Network Isolation:</strong> Sever the machine's network connection instantly to terminate the attacker's interactive session and halt any ongoing data exfiltration.</li>\n<li><strong>Hunt for Lateral Movement:</strong> Because QuasarRAT is often used as a beachhead, incident responders must assume the attacker has attempted to move laterally. EDR and Active Directory logs must be scrutinized for compromised credentials and unauthorized access to other internal hosts.</li>\n<li><strong>Total Re-imaging and Credential Rotation:</strong> The machine cannot be trusted and must be wiped to bare metal. All credentials (user, service accounts) that were exposed to or logged into the compromised machine must be immediately reset.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "RAT.Quasar",
    "Backdoor.MSIL.Quasar",
    "Win32/Quasar"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1071.001",
    "T1056.001",
    "T1055"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-02T07:45:39Z",
  "type": "Remote Access Trojan (RAT)",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}