| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
QuasarRAT can retrieve files from compromised client machines. |
| T1010 Application Window Discovery |
APT-C-36 used a customized version of QuasarRAT to monitor browser windows for strings relating to specific Colombian financial institutions. |
| T1016 System Network Configuration Discovery |
QuasarRAT has the ability to enumerate the Wide Area Network (WAN) IP through requests to ip-api[.]com, freegeoip[.]net, or api[.]ipify[.]org observed with user-agent string `Mozilla/5.0 (Windows NT 6.3; rv:48.0) Gecko/20100101 Firefox/48.0`. |
| T1021.001 Remote Desktop Protocol |
QuasarRAT has a module for performing remote desktop access. |
| T1033 System Owner/User Discovery |
QuasarRAT can enumerate the username and account type. |
| T1053.005 Scheduled Task |
QuasarRAT contains a .NET wrapper DLL for creating and managing scheduled tasks for maintaining persistence upon reboot. |
| T1056.001 Keylogging |
QuasarRAT has a built-in keylogger. |
| T1059.003 Windows Command Shell |
QuasarRAT can launch a remote shell to execute commands on the victim’s machine. |
| T1082 System Information Discovery |
QuasarRAT can gather system information from the victim’s machine including the OS type. |
| T1090 Proxy |
QuasarRAT can communicate over a reverse proxy using SOCKS5. |
| T1095 Non-Application Layer Protocol |
QuasarRAT can use TCP for C2 communication. |
| T1105 Ingress Tool Transfer |
QuasarRAT can download files to the victim’s machine and execute them. |
| T1112 Modify Registry |
QuasarRAT has a command to edit the Registry on the victim’s machine. |
| T1125 Video Capture |
QuasarRAT can perform webcam viewing. |
| T1547.001 Registry Run Keys / Startup Folder |
If the QuasarRAT client process does not have administrator privileges it will add a registry key to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` for persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.