logo

Under the SADBRIDGE with GOSAR: QUASAR Gets a Golang Rewrite

ID: 868c7b8f-de9d-5f28-89e8-cbc038da218b

STIX ID: report--868c7b8f-de9d-5f28-89e8-cbc038da218b

Feed Name: Elastic Security Labs

Threat Score
80/100

Date Published: 2024-12-13

Date Updated: 2026-04-27

...
...

Elastic Security Labs identified an active, organized campaign (REF3864) targeting Chinese-language users with trojanized installers that use a custom loader named SADBRIDGE to side-load malicious DLLs and inject a new Golang-based Quasar reimplementation called GOSAR. The report details multi-stage injection, UAC/task-scheduler privilege escalation, persistence via services and scheduled tasks, extensive anti-analysis and AV-evasion techniques, GOSAR’s multi-platform features (keylogging, HVNC, plugins, logging, firewall/hosts modifications), and provides IOCs and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.