Malware

Quasar RAT

Also known as: CinaRAT · QuasarRAT · Yggdrasil

Quasar RAT is a malware family written in .NET which is used by a variety of attackers. The malware is fully functional and open source, and is often packed to make analysis of the source more difficult.

Indicators of Compromise 51

Domain 6789x[.]site Domain adminapi[.]tippusoni[.]in Domain archive[.]org Domain begalinokotobananinotrippitroppacrocofanclub[.]su Domain cel-robox[.]com Domain healthymagination[.]com Domain krogeralbertsons[.]com Domain m-vn[.]ws Domain maxfactor-international[.]com Domain myaunet[.]su Domain paste[.]ee Domain rezilion[.]com Domain snsystems[.]com Domain solidity[.]bot Domain vn[.]xyz Filename 1.txt Filename 2.txt Filename 3.txt Filename C:\Windows\System32\drivers\etc\hosts:cache Filename Launch.exe Filename a.txt Filename a.vbs Filename acpi_pad.ko Filename back.bat Filename back.txt Filename bai.bat Filename check_paths.py Filename demo.pdb Filename deploy_implant.py Filename deploy_shell.py Filename dll.zip Filename extension.zip Filename myau.exe Filename myaunet.exe Filename prcc1.rar Filename service.pdb Filename sss.ashx Filename svchosts.exe Filename up.ashx Filename user.bat Filename wmam.exe GitHub Repo widestring-1.2.1 SHA-256 209fb5bb2440ffe1a631dfe3b574229105a33c5153eded023cc77d8e8f81d1de SHA-256 a1eadd41327bd8736e275627d3953944fe7089c032d72a3e429ff18ad0958ada SHA-256 c3684164933c3f54d5b0b242a8a906a85d633de479079a820bb804c0f73c0f58 SHA-256 c5c0228a1e0ba2bb748219325f66acf17078a26165b45728d8e98150377aa068 SHA-256 ce72b79e324371134db762fe70b8b1789af899d7217461bc3658a6bd84743eb6 SHA-256 e0ca66c1a9a68b319b24a7c6b8fdca219dffd802dd4de2d59f602c4d90f40d6c SHA-256 e19d5d8f941b9a98fbb3b65e1e6077fa00d97529e351e455297b0204ec07e9ed IP 139[.]180[.]197[.]150 Registry User index.crates.io-1949cf8c6b5b557f

MITRE ATT&CK TTPs 38

T1055
Process Injection
Defense Evasion
T1055.003
Thread Execution Hijacking
Defense Evasion
T1059.001
PowerShell
Execution
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1071.001
Web Protocols
Command And Control
T1074
Data Staged
Collection
T1078
Valid Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1090
Proxy
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1110
Brute Force
Credential Access
T1112
Modify Registry
Defense Evasion
T1129
Shared Modules
Execution
T1134
Access Token Manipulation
Defense Evasion
T1137
Office Application Startup
Persistence
T1140
Deobfuscate/Decode Files or Information
Defense Evasion
T1176
Browser Extensions
Persistence
T1190
Exploit Public-Facing Application
Initial Access
T1197
BITS Jobs
Defense Evasion
T1203
Exploitation for Client Execution
Execution
T1204.002
Malicious File
Execution
T1210
Exploitation of Remote Services
Lateral Movement
T1211
Exploitation for Defense Evasion
Defense Evasion
T1218
System Binary Proxy Execution
Defense Evasion
T1218.011
Rundll32
Defense Evasion
T1484.001
Group Policy Modification
Defense Evasion
T1497.001
System Checks
Defense Evasion
T1547.001
Registry Run Keys / Startup Folder
Persistence
T1553.005
Mark-of-the-Web Bypass
Defense Evasion
T1566
Phishing
Initial Access
T1570
Lateral Tool Transfer
Lateral Movement
T1571
Non-Standard Port
Command And Control
T1573
Encrypted Channel
Command And Control
T1574.002
DLL Side-Loading
Persistence
T1583
Acquire Infrastructure
Resource Development
T1584
Compromise Infrastructure
Resource Development
T1586
Compromise Accounts
Resource Development
T1595.002
Vulnerability Scanning
Reconnaissance

Source Articles

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos identified a Chinese-speaking threat actor, UAT-10147, conducting a global campaign targeting Windows and Linux web servers in government, education, media, technology, and gaming sectors. The actor leverages publicly disclosed vulnerabilities for initial access, including CVE-2022-27925, CVE-2021-23758, and CVE-2019-18935, and uses AI-driven tooling to automate exploitation, reconnaissance, payload generation, and validation. Post-compromise, the actor deploys malware such as QuasarRAT, Gh0stCringe, and SPECTRE, establishes persistence via scheduled tasks and rogue user accounts, and uses AI-generated scripts to refine attacks and bypass defenses. A misconfigured command-and-control server at 139.180.197[.]150 exposed operational details, including a target list of 170,000 URLs and AI-assisted attack workflows.
talos ·3w ago
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
UAT-10147, a Chinese-speaking threat actor, is deploying a new cross-platform backdoor named SPECTRE that targets both Windows and Linux systems. The implant includes advanced capabilities such as process injection, credential theft, anti-analysis routines, and EDR evasion via Bring Your Own Vulnerable Driver (BYOVD) techniques. On Linux, SPECTRE deploys a kernel rootkit called Specter, disguised as 'acpi_pad.ko', which uses ftrace-based hooking to hide processes, modules, and enable UID 0 escalation. The actor also leverages SEO fraud tools like BadIIS and a custom ASHX web handler targeting Vietnamese users, along with multiple backdoors including Meterpreter, Noodle RAT, QuasarRAT, and Gh0stCringe for persistence.
talos ·3w ago
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actor Sable Squirrel has spent nearly $7 million acquiring expired domains to exploit their inherited reputation, traffic, and backlinks for illegal sports streaming, online gambling promotion, and malware distribution. The group operates a dual-purpose infrastructure where re-registered domains serve both as streaming platforms and command-and-control (C2) servers for malware such as Quasar RAT and HiddenTear ransomware. The operation targets users in Asia and Australia through social media and ad networks, using a traffic distribution system to redirect victims while evading detection. Additional scavenger actors like Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel are also abusing expired domains for ad fraud, tech support scams, and traffic resale.
hacker-news ·4w ago
The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions | Datadog Security Labs
MUT-9332 is a threat actor targeting Solidity developers via malicious Visual Studio Code extensions named solaibot, among-eth, and blankebesxstnion. These extensions deliver multi-stage malware that establishes persistence, disables security controls, and exfiltrates cryptocurrency wallet credentials. The campaign uses obfuscated scripts, steganography, and multiple command-and-control domains to evade detection, with infrastructure reuse indicating links to a prior Monero cryptominer campaign.
Datadog Security Labs