QuasarRAT - Daily Threat Report

Sunday, July 12, 2026

Daily Summary

QuasarRAT activity surged on 2026-07-12 with 11 new samples, a 75% increase over the 7-day average of 6. This marks a notable escalation in sample generation volume, though no new C2 infrastructure was observed.

New Samples Detected

All 11 samples were single-file implants, with 7 .exe binaries, 3 .bat scripts, and 1 file using the unusual extension .52397922. The .bat samples suggest continued reliance on script-based initial payloads that may execute PowerShell or download additional stages. The .52397922 extension is atypical and could represent either a renamed .scr or an encrypted container - this warrants closer examination for packing or obfuscation techniques.

7-Day Trend

Today’s 11 samples represent a 75% increase versus the 7-day average of 6, confirming an upward trend in new sample creation. This deviation exceeds the 25% threshold and suggests either renewed campaign activity or updated builder configurations.

IOC Highlights

11 new IOCs were generated from today’s samples, all tied to the file hashes and associated file paths. No new C2 domains or IPs were added, indicating the operators may be recycling existing infrastructure while churning out fresh payloads - a common evasion pattern to bypass hash-based detection.

Security Analysis

The absence of new C2 infrastructure alongside a 75% sample volume increase is unusual and closely mirrors behavior seen in QuasarRAT campaigns from mid-2025 where operators rotated payload hashes without changing command-and-control servers. This suggests the group behind today’s samples is likely engaged in targeted re-delivery against previously infected networks, attempting to re-establish persistence after cleanup. Defenders should audit all endpoints for connections to known QuasarRAT C2 IPs maintained in intelligence feeds and prioritize blocking the .52397922 file extension at email gateways as an indicator of this variant’s delivery.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More QuasarRAT Reports

Recent Malware Reports