logo

QuasarRAT Core Functionalities Along with Encrypted Configuration and Obfuscation Techniques Exposed

ID: 3b95bab5-8f54-55db-8bca-47ccaf411096

STIX ID: report--3b95bab5-8f54-55db-8bca-47ccaf411096

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

QuasarRAT, a .NET/C# remote administration tool that has been widely repurposed by attackers since 2014, is examined for its capabilities (system reconnaissance, file management, keystroke logging, command execution) and its attractiveness due to open-source availability. The report details advanced obfuscation in malicious builds — including AES-256-CBC encryption of configuration with PBKDF2-derived keys and hardcoded salts — and describes analyst techniques (dnlib, IL inspection, locating static constructors and decryption routines) to extract cryptographic material and decrypt configuration to reveal C2 infrastructure and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.