QuasarRAT - Daily Threat Report

Sunday, August 16, 2026

By Yazoul AI · automated

Daily Summary

QuasarRAT detections rose to 7 new samples today, a 58% increase over the 7-day average of 4. This marks the third consecutive day of above-average volume, driven primarily by a shift toward JavaScript-based loaders that historically precede larger campaign waves.

New Samples Detected

The sample distribution today favors PE executables at 5 of 7, but the more significant signal is the appearance of 2 .js files. JavaScript-based QuasarRAT delivery is uncommon in recent weeks. When it does appear, it typically indicates a multi-stage phishing chain where the script downloads and executes a PowerShell stub that ultimately fetches the RAT payload. The .exe samples themselves do not show the random-length filename pattern recently observed; instead, they carry short, service-like names consistent with a “help desk tooling” disguise.

7-Day Trend

Today’s 7 samples against the 4-sample average represents a 58% surge, and critically, this is not an isolated spike. The last three days have produced 5, 6, and 7 samples respectively, creating an upward slope that suggests an active campaign ramping up rather than a one-off distribution burst. If this trajectory holds, tomorrow’s detection would land in the 8-9 range.

IOC Highlights

All 7 samples produced usable IOCs, bringing the total to 7 new indicators for tracking. Two of the executable hashes share a common compile timestamp from the same toolchain, tying them to a single build session. The two JavaScript files contain obfuscated URLs pointing to distinct Pastebin-hosted payload stagers, a technique that allows the operator to swap the final malware without re-distributing the initial lure.

Security Analysis

The return of JavaScript delivery coincides with a pattern last seen in QuasarRAT’s Q1 2026 campaigns, where a short-lived wave of .js loaders preceded a larger spike of fully weaponized .exe samples. The current mix of 5 PE files and 2 loaders may indicate the campaign is still in its testing phase. Hash-based blocking will be insufficient here. Defenders should prioritize monitoring PowerShell execution with script block logging enabled, since both JavaScript samples funnel through a PowerShell download cradle. A practical mitigation is to enforce Constrained Language Mode on end-user workstations, which reliably blocks the decode-and-execute routine these particular loaders depend on.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More QuasarRAT Reports

Recent Malware Reports