MaxXor. (n.d.). QuasarRAT. Retrieved July 10, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
ToolQuasarRAT | QuasarRAT has a module for performing remote desktop access. |
| T1056.001 Keylogging |
ToolQuasarRAT | QuasarRAT has a built-in keylogger. |
| T1059.003 Windows Command Shell |
ToolQuasarRAT | QuasarRAT can launch a remote shell to execute commands on the victim’s machine. |
| T1082 System Information Discovery |
ToolQuasarRAT | QuasarRAT can gather system information from the victim’s machine including the OS type. |
| T1090 Proxy |
ToolQuasarRAT | QuasarRAT can communicate over a reverse proxy using SOCKS5. |
| T1105 Ingress Tool Transfer |
ToolQuasarRAT | QuasarRAT can download files to the victim’s machine and execute them. |
| T1112 Modify Registry |
ToolQuasarRAT | QuasarRAT has a command to edit the Registry on the victim’s machine. |
| T1125 Video Capture |
ToolQuasarRAT | QuasarRAT can perform webcam viewing. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolQuasarRAT | If the QuasarRAT client process does not have administrator privileges it will add a registry key to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` for persistence. |
| T1552.001 Credentials In Files |
ToolQuasarRAT | QuasarRAT can obtain passwords from FTP clients. |
| T1555 Credentials from Password Stores |
ToolQuasarRAT | QuasarRAT can obtain passwords from common FTP clients. |
| T1555.003 Credentials from Web Browsers |
ToolQuasarRAT | QuasarRAT can obtain passwords from common web browsers. |
| T1573.001 Symmetric Cryptography |
ToolQuasarRAT | QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.