RAT
QuasarRAT
RAT
5 detections found
Also known as: Quasar RAT, xRAT, CinaRAT, Yggdrasil
QuasarRAT is an open-source, C#-based remote administration tool that has been publicly available on GitHub since 2014, offering keylogging, remote desktop, file management, and reverse-proxy capabilities. Its legitimate open-source status makes it attractive to a wide range of operators, from commodity criminals to state-sponsored groups: Mandiant/Google Cloud Threat Intelligence has documented China-linked APT10 (menuPass) using customized versions of QuasarRAT (including forks requiring a custom AES-decrypting dropper) as a second-stage backdoor in espionage operations.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- QuasarRAT, Software S0262 — MITRE ATT&CK
- APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat — Mandiant / Google Cloud
Detection rules
| Source | Rule | Status | Updated |
|---|---|---|---|
| suricata | ET MALWARE Win32/XRat.AT Variant CnC Activity | rev 2 | 2021-04-29 |
| yara | MSILStealer | — | — |
| yara | xRAT | — | — |
| yara | xRAT20 | — | — |
| yara | HKTL_NET_GUID_CinaRAT | — | — |