Live Training | What's New in Lumu Defender

Already have an account? Sign in

Sign in

Malware

S0262

QuasarRAT

Type

Remote Administration Tool (RAT)

Associated threat actors

Various

Key Capabilities

Provides remote access and control, enabling keystroke logging, screen capture, audio and video recording, and password theft.

OS Targeted

Windows

IoCs on Maltiverse

Maltiverse provides updated IoCs for easy SIEM/SOAR/Firewall/EDR integration.

What is QuasarRAT?

QuasarRAT (S0262) is an open-source Remote Administration Tool (RAT). Cybercriminals use this potent tool for data theft and system control.

It operates stealthily, giving attackers a wide range of capabilities. These include a keylogger to capture credentials, screen and video capture for surveillance, and the ability to steal saved passwords from browsers. Attackers can also execute commands, manage files on the infected system, and move laterally within a network.

How to Defend Against QuasarRAT?

Defending against QuasarRAT requires preventing the initial infection and detecting its command-and-control (C2) activity.

  • Be cautious with email attachments and downloads, which are the primary delivery vectors for this malware.
  • Keep all operating systems and software patched to limit the vulnerabilities that can be exploited for initial access.
  • Deploy endpoint detection to identify and block the execution of known RATs and their associated behaviors.
  • Use network detection (NDR) with integrated threat intelligence to spot and block QuasarRAT’s C2 communications.

Join our pre-day 
workshop waitlist

By clicking “Submit Request” you agree to the Lumu Terms of Service and Privacy Policy.