QuasarRAT - Daily Threat Report

Sunday, July 19, 2026

Daily Summary

QuasarRAT activity declined notably on July 19, with only 5 new samples detected versus the 7-day average of 8. This 36% drop is the largest single-day decrease observed over the past week, likely reflecting weekend lulls in distribution campaigns rather than a tactical shift. No new C2 servers were observed, though 5 new IOCs warrant attention.

7-Day Trend

Today’s volume of 5 new samples represents a significant deviation from the 7-day average of 8 (more than 25% below the baseline). This marks the third consecutive day of below-average activity following a moderate surge on July 14 and 15. The decline is consistent with periodic reprieves in QuasarRAT distribution, which typically precede a new campaign wave within 48-72 hours.

New Samples Detected

All 5 samples followed QuasarRAT’s standard pattern: 4 executable files (.exe) and 1 HTA script. The .hta sample is notable as this file type accounts for only 20% of today’s total but represents a potential shift in initial access vectors. HTA-based delivery allows for easy embedding in phishing emails and can bypass certain email gateways that scan for .exe attachments.

IOC Highlights

The 5 new IOCs are currently limited to file hashes. No new C2 domains, IPs, or URLs were identified, suggesting the operators are reusing existing infrastructure or have temporarily scaled back command-and-control activity. The hashes have been added to Yazoul Security’s tracker for automated correlation.

Security Analysis

The appearance of an .hta sample among today’s QuasarRAT detections, combined with the overall decline in sample volume, mirrors patterns seen in previous QuasarRAT campaigns where operators experimented with alternative loaders between major distribution pushes. The HTA vector is particularly effective against organizations that block .exe attachments but fail to restrict execution of script-based file types. Defenders should audit email filtering rules to ensure .hta files are quarantined alongside .exe attachments, especially given QuasarRAT’s history of pairing HTA droppers with decoy documents to evade detection.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More QuasarRAT Reports

Recent Malware Reports