QuasarRAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
November 11, 2025
Last Seen
July 23, 2026

QuasarRAT is a Windows remote access Trojan (RAT) that allows attackers to remotely control infected machines.

Overview

QuasarRAT is a Windows remote access Trojan (RAT) that allows attackers to remotely control infected machines. Recent disclosures highlight its core functionalities, encrypted configuration, and obfuscation techniques, underscoring its persistence and evasion capabilities. Its long-standing presence and modular features keep it relevant for defenders tracking RAT activity.

Related Threat Clusters

  • MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

    In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…

    16 articles · Updated July 22, 2026
  • Operation Endgame Disrupts Major Malware Networks Rhadamanthys, VenomRAT, and Elysium

    Law enforcement from nine countries has dismantled over 1,000 servers associated with the Rhadamanthys infostealer, VenomRAT remote access Trojan, and Elysium botnet during Operation Endgame. This operation, coordinated…

    8 articles · Updated November 13, 2025
  • Five Plead Guilty in North Korean IT Worker Fraud Scheme

    Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…

    39 articles · Updated November 17, 2025
  • xRAT Malware Targets Windows Users via Fake Adult Game

    A new malware, xRAT (QuasarRAT), has been identified targeting Windows users in Korea through webhard file-sharing services. Disguised as fake adult games, this remote access trojan employs advanced evasion techniques…

    3 articles · Updated January 9, 2026
  • Lazarus Group Linked to $30M Upbit Hack in South Korea

    South Korean authorities suspect that North Korea's Lazarus Group was behind a hack of Upbit, resulting in losses of approximately $30.4 million. The breach involved unusual activity in Solana tokens and led Upbit to…

    100 articles · Updated November 28, 2025
  • QuasarRAT Exposed: Core Functionalities and Obfuscation Techniques Revealed

    The core functionalities of QuasarRAT, a remote access trojan, have been exposed, revealing its encrypted configuration and obfuscation techniques. This malware poses risks to users by enabling unauthorized access to…

    2 articles · Updated December 8, 2025
  • Cybercrime Crackdown Targets Malware and AI Threats

    Law enforcement and cybersecurity firms have launched intensified operations against cybercrime, focusing on sophisticated malware networks and supply chain attacks. Collaborators including CrowdStrike, Europol, and the…

    15 articles · Updated November 18, 2025
  • Operation Endgame 3.0 Disrupts Major Malware Networks

    Europol and law enforcement agencies from 11 countries executed Operation Endgame 3.0 from November 10 to 13, 2025, dismantling the infrastructure of three major malware operations: Rhadamanthys, VenomRAT, and Elysium.…

    20 articles · Updated November 24, 2025

Recent Intelligence Reports

  • 003 — attack.mitre.org · July 23, 2026
  • xRAT Malware Attacking Windows Users Disguised as Adult Game — Cybersecuritynews · January 9, 2026
  • QuasarRAT Core Functionalities Along with Encrypted Configuration and Obfuscation Techniques Exposed — Cybersecuritynews · December 8, 2025
  • Exposing the Core Functionalities of QuasarRAT: Encrypted Configuration and Obfuscation Techniques — Gbhackers · December 8, 2025
  • Operation Endgame 3.0 Takes Down 3 Major Global Malware Networks — Linkedin · November 13, 2025
  • Operation Endgame 3.0 Dismantles Three Major Malware Networks — Infosecurity-Magazine · November 13, 2025
  • Android Devices Targeted By KONNI APT in Find Hub Exploitation — Infosecurity-Magazine · November 11, 2025
  • North Korean spies turn Google's Find Hub into remote — Theregister · November 11, 2025

CVSS v3.1 Breakdown