ATT&CKReferencesGitHub QuasarRAT

GitHub QuasarRAT

MaxXor. (n.d.). QuasarRAT. Retrieved July 10, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
ToolQuasarRAT

QuasarRAT has a module for performing remote desktop access.

T1056.001
Keylogging
ToolQuasarRAT

QuasarRAT has a built-in keylogger.

T1059.003
Windows Command Shell
ToolQuasarRAT

QuasarRAT can launch a remote shell to execute commands on the victim’s machine.

T1082
System Information Discovery
ToolQuasarRAT

QuasarRAT can gather system information from the victim’s machine including the OS type.

T1090
Proxy
ToolQuasarRAT

QuasarRAT can communicate over a reverse proxy using SOCKS5.

T1105
Ingress Tool Transfer
ToolQuasarRAT

QuasarRAT can download files to the victim’s machine and execute them.

T1112
Modify Registry
ToolQuasarRAT

QuasarRAT has a command to edit the Registry on the victim’s machine.

T1125
Video Capture
ToolQuasarRAT

QuasarRAT can perform webcam viewing.

T1547.001
Registry Run Keys / Startup Folder
ToolQuasarRAT

If the QuasarRAT client process does not have administrator privileges it will add a registry key to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` for persistence.

T1552.001
Credentials In Files
ToolQuasarRAT

QuasarRAT can obtain passwords from FTP clients.

T1555
Credentials from Password Stores
ToolQuasarRAT

QuasarRAT can obtain passwords from common FTP clients.

T1555.003
Credentials from Web Browsers
ToolQuasarRAT

QuasarRAT can obtain passwords from common web browsers.

T1573.001
Symmetric Cryptography
ToolQuasarRAT

QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.