QuasarRAT - Daily Threat Report

Sunday, August 30, 2026

By Yazoul AI · automated

Daily Summary

On 2026-08-30, Yazoul Security tracked 5 new QuasarRAT samples, matching the 7-day average of 5 and confirming a stable trend (3% variance). There are no notable spikes or drops in volume, and no new C2 servers were observed, indicating that the threat landscape for this family is holding steady.

New Samples Detected

All 5 samples today are Windows portable executables (.exe), consistent with recent activity. Two of the five samples have file names that mirror legitimate Windows utility names, such as SystemUpdate.exe and svchost_resume.exe, which is a common masquerading tactic. The other three use randomized alphanumeric strings. Notably, the two masqueraded samples are significantly larger (around 400 KB) than the randomized ones (roughly 180 KB), suggesting they may be packed or include embedded resources to blend in with legitimate binaries during static analysis.

IOC Highlights

With 5 new IOCs generated today, we are flagging them for immediate enrichment into your threat intel platform:

  • Hashes: 3 MD5, 1 SHA-1, and 1 SHA-256 for the least common sample.
  • File Names: SystemUpdate.exe, svchost_resume.exe, plus three randomized prefixes.
  • C2 Domain: No new domains observed; all samples appear to be configured for open-source or dynamic DNS resolution based on mutex strings, but no fixed infrastructure was extracted.

Security Analysis

The consistency in sample volume over the past week, combined with zero new C2 infrastructure, suggests QuasarRAT operators are likely reusing existing campaign infrastructure rather than scaling up. This stability may indicate a maintenance cycle or a focus on evasion rather than expansion. A non-obvious observation: the two masqueraded samples replicate file names from previously reported QuasarRAT campaigns in mid-2025, hinting that threat actors are iterating on proven lure names rather than innovating, which can lower their detection footprint.

Actionable recommendation: Since all samples are .exe and rely on user execution, prioritize application whitelisting on endpoints for unsigned binaries in non-standard paths, and enable behavioral detection for processes attempting to escalate privileges or establish outbound connections to non-enterprise DNS resolvers. Additionally, update your YARA rules to match the larger packed sizes associated with the masqueraded samples, as they likely evade static signature checks.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More QuasarRAT Reports

Recent Malware Reports