S0262: QuasarRAT
Security context for executives and security teams
QuasarRAT matters because it is a publicly available Windows remote access tool, not a one-off malware family. Its open-source availability lowers the barrier for different actors to reuse or modify it, so defenders should treat it as a coverage problem around RAT behaviors: persistence, discovery, command execution, credential and data collection, file transfer, remote access, and command-and-control.
Executive priority
Prioritize validation of Windows endpoint, identity, and network visibility rather than relying on a single signature for QuasarRAT. The ATT&CK relationships show use by multiple named groups and a broad set of techniques, making this relevant to incident readiness, audit evidence for endpoint controls, and resilience against remote-control intrusions that can support espionage or follow-on compromise.
Technical view
The object is a Windows tool with no official ATT&CK detection text. SOC and IR teams should validate behavioral coverage for the related techniques: command shell execution, scheduled task creation, registry Run key/startup persistence, registry modification, UAC bypass indicators, RDP logons, system/user/network/application-window discovery, local data and credential-file access, keylogging or video-capture indicators where telemetry exists, ingress tool transfer, proxy behavior, and non-application-layer C2 patterns. Because QuasarRAT is open source, detections should not depend only on static names or hashes.
Likely telemetry
- Windows endpoint process creation and command-line telemetry
- Scheduled task creation and modification events
- Windows Registry modification telemetry, especially Run keys and startup locations
- Authentication and logon telemetry for RDP sessions
- Endpoint file creation, download, and tool-transfer evidence
Detection direction
- Map existing detections to the related ATT&CK techniques instead of treating QuasarRAT as a single indicator-based alert.
- Tune for suspicious combinations: persistence plus command shell execution, discovery followed by file transfer, or RDP activity paired with new tools or registry changes.
- Review false positives for administrative tools that legitimately create scheduled tasks, modify Run keys, use RDP, or transfer files.
- Confirm whether endpoint telemetry can observe collection behaviors such as keylogging, camera access, and credential-file searching; many environments have blind spots here.
- Use relationship context as threat-intelligence enrichment only; the supplied data supports that multiple groups have used the tool, not that any specific actor is present in a local incident.
Mitigation priorities
- Harden Windows endpoints against unauthorized persistence through scheduled tasks, startup folders, and registry Run keys.
- Restrict and monitor RDP exposure and require strong account controls for remote access.
- Apply least privilege and reduce local administrator rights to limit UAC bypass and persistence opportunities.
- Control outbound traffic and investigate unusual proxy or non-standard protocol communications.
- Reduce credential exposure in files through secrets hygiene, configuration review, and access control.
Additional notes and limits
ATT&CK identifies QuasarRAT as an open-source C# remote access tool publicly available on GitHub since at least 2014. The supplied relationships connect it to multiple groups and many techniques, but the object itself has no specified tactics and no official detection guidance.
This take is limited to the supplied ATT&CK fields, references, and relationships. It does not assert current exploitation, customer exposure, specific indicators, malware variants, or guaranteed detection. Local telemetry, baselines, and incident evidence are required to determine coverage and relevance.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
QuasarRAT
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
