QuasarRAT - Daily Threat Report

Sunday, August 9, 2026

By Yazoul AI · automated

Daily Summary

QuasarRAT activity on 2026-08-09 remains stable, with 4 new samples detected against a 7-day average of 4 (7% variance). No new C2 infrastructure or geographic shifts were observed, indicating a continuation of existing operational patterns rather than a new campaign push.

New Samples Detected

The 4 samples break down as 3 Windows executables and 1 batch script (.bat). The batch file is the notable deviation from the norm, as it suggests an attempt to execute QuasarRAT via a scripted dropper rather than direct PE execution. This could indicate either a low-sophistication operator testing delivery methods or a targeted scenario where the batch file is used to stage the payload behind legitimate-looking commands. The .exe samples show no naming anomalies, consistent with prior weeks.

Detection Rate

No new variants or packing techniques were identified in today’s samples. The .bat wrapper, however, warrants attention: if it is using PowerShell or certutil to fetch and execute the payload, it may bypass static AV scanning that does not fully inspect script content. This is not a new evasion method for QuasarRAT, but its appearance here suggests the actor is iterating on delivery rather than on the payload itself.

IOC Highlights

4 new IOCs were added to the tracker, all tied to today’s samples. Given the low volume, these are likely file hashes and the batch script’s URL or command string. Analysts should prioritize the .bat file’s embedded download location, as identifying that C2 or staging URL may reveal a broader operational cluster not yet mapped.

Security Analysis

The persistence of a 4-sample daily average over multiple weeks, with zero new C2 infrastructure, points to a single operator or small group maintaining a steady but unambitious campaign. This stands in contrast to historical QuasarRAT spikes that coincide with new loader-as-a-service offerings. The use of a .bat file today is a minor tactical shift, but it aligns with a pattern seen in 2025 where actors alternated between direct PE drops and scripted execution to test detection gaps.

Actionable recommendation: Ensure EDR policies flag execution of untrusted .bat files that invoke PowerShell or download agents, and specifically hunt for certutil or bitsadmin usage in combination with QuasarRAT process names. Since C2 infrastructure is static, blocking known domains remains effective, but validation of the .bat dropper’s target URL should be immediate to prevent the pivot to a new staging domain.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More QuasarRAT Reports

Recent Malware Reports