QuasarRAT

S0262

Tool.View on attack.mitre.org

About this tool

QuasarRAT is an open-source, remote access tool that has been publicly available on GitHub since at least 2014. QuasarRAT is developed in the C# language.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1005
Data from Local System

QuasarRAT can retrieve files from compromised client machines.

T1010
Application Window Discovery

APT-C-36 used a customized version of QuasarRAT to monitor browser windows for strings relating to specific Colombian financial institutions.

T1016
System Network Configuration Discovery

QuasarRAT has the ability to enumerate the Wide Area Network (WAN) IP through requests to ip-api[.]com, freegeoip[.]net, or api[.]ipify[.]org observed with user-agent string `Mozilla/5.0 (Windows NT 6.3; rv:48.0) Gecko/20100101 Firefox/48.0`.

T1021.001
Remote Desktop Protocol

QuasarRAT has a module for performing remote desktop access.

T1033
System Owner/User Discovery

QuasarRAT can enumerate the username and account type.

T1053.005
Scheduled Task

QuasarRAT contains a .NET wrapper DLL for creating and managing scheduled tasks for maintaining persistence upon reboot.

T1056.001
Keylogging

QuasarRAT has a built-in keylogger.

T1059.003
Windows Command Shell

QuasarRAT can launch a remote shell to execute commands on the victim’s machine.

T1082
System Information Discovery

QuasarRAT can gather system information from the victim’s machine including the OS type.

T1090
Proxy

QuasarRAT can communicate over a reverse proxy using SOCKS5.

T1095
Non-Application Layer Protocol

QuasarRAT can use TCP for C2 communication.

T1105
Ingress Tool Transfer

QuasarRAT can download files to the victim’s machine and execute them.

T1112
Modify Registry

QuasarRAT has a command to edit the Registry on the victim’s machine.

T1125
Video Capture

QuasarRAT can perform webcam viewing.

T1547.001
Registry Run Keys / Startup Folder

If the QuasarRAT client process does not have administrator privileges it will add a registry key to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` for persistence.

View all 25 procedure examples

Groups that use it7

Campaigns0

None recorded.

References2

  1. GitHub QuasarRAT Open source
    MaxXor. (n.d.). QuasarRAT. Retrieved July 10, 2018.
  2. Volexity Patchwork June 2018 Open source
    Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.