QuasarRAT Core Functionalities Along with Encrypted Configuration and Obfuscation Techniques Exposed
ID: 3b95bab5-8f54-55db-8bca-47ccaf411096
STIX ID: report--3b95bab5-8f54-55db-8bca-47ccaf411096
Feed Name: cybersecurityNews.com
QuasarRAT, a .NET/C# remote administration tool that has been widely repurposed by attackers since 2014, is examined for its capabilities (system reconnaissance, file management, keystroke logging, command execution) and its attractiveness due to open-source availability. The report details advanced obfuscation in malicious builds — including AES-256-CBC encryption of configuration with PBKDF2-derived keys and hardcoded salts — and describes analyst techniques (dnlib, IL inspection, locating static constructors and decryption routines) to extract cryptographic material and decrypt configuration to reveal C2 infrastructure and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
