1200KM / tool
QuasarRAT — Attack Tool
QuasarRAT is an open-source, remote access tool that has been publicly available on GitHub since at least 2014. QuasarRAT is developed in the C# language.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: QuasarRAT, xRAT
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- Patchwork · G0040 · Pinned relationship source (relationship--5d26097f-2d6a-4642-857b-109c0f600a73)
- menuPass · G0045 · Pinned relationship source (relationship--a552bf3d-a438-406f-8f5b-8e263adad080)
- Gorgon Group · G0078 · Pinned relationship source (relationship--9839e4e4-06c2-4f6a-8fe0-bc556e547536)
- Kimsuky · G0094 · Pinned relationship source (relationship--9f259569-dfd2-4afa-aa0a-8031864c1367)
- APT-C-36 · G0099 · Pinned relationship source (relationship--c303e231-4201-4c17-a3fa-bcb0bbdad0d9)
- BackdoorDiplomacy · G0135 · Pinned relationship source (relationship--bc592166-c29c-4913-b8a0-ec266321a325)
- LazyScripter · G0140 · Pinned relationship source (relationship--878ff6f7-d372-4559-a114-8858eb2682d4)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1005 · Data from Local System · Detection rules & anomalies
- T1010 · Application Window Discovery · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1021.001 · Remote Desktop Protocol · Detection rules & anomalies
- T1033 · System Owner/User Discovery · Detection rules & anomalies
- T1053.005 · Scheduled Task · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1090 · Proxy · Detection rules & anomalies
- T1095 · Non-Application Layer Protocol · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1112 · Modify Registry · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1547.001 · Registry Run Keys / Startup Folder · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1553.002 · Code Signing · Detection rules & anomalies
- T1555 · Credentials from Password Stores · Detection rules & anomalies
- T1555.003 · Credentials from Web Browsers · Detection rules & anomalies
- T1564.001 · Hidden Files and Directories · Detection rules & anomalies
- T1564.003 · Hidden Window · Detection rules & anomalies
- T1571 · Non-Standard Port · Detection rules & anomalies
- T1573.001 · Symmetric Cryptography · Detection rules & anomalies
- T1614 · System Location Discovery · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Cloud Service Enumeration · DC0083
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Firewall Rule Modification · DC0051
- Firmware Modification · DC0004
- Instance Enumeration · DC0075
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Scheduled Job Creation · DC0001
- Scheduled Job Modification · DC0012
- Script Execution · DC0029
- Service Creation · DC0060
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.