A recent report from Uptycs highlighted the evolution of QuasarRAT, an open-source remote administration tool (RAT) that has many malicious capabilities. According to Uptycs security researcher Tejaswini Sandapolla, QuasarRAT, also known as CinaRAT or Yggdrasil, uses a sophisticated technique called DLL side-loading, which exploits trusted Microsoft to perform malicious activities.

This technique exploits the trust in these files in the Windows environment and is therefore very dangerous. QuasarRAT was reportedly accessible on GitHub , putting Windows users , system administrators, and cybersecurity professionals at risk
See also: SeroXen RAT: Infects NuGet developers
“ Such tactics are not new, but seeing them evolve and be adopted by other malware strains shows the adaptability of threat actors , ” Sandapolla wrote. In fact, the attackers are using specific trusted Microsoft files to carry out this attack.
In the initial phase of the attack, QuasarRAT uses the genuine “ ctfmon.exe ” to load a malicious DLL, disguising its intentions. This allows the attacker to obtain a ‘stage 1’ payload, which will act as a gateway for subsequent malicious activities. The stage 1 payload then releases both the legitimate “calc.exe” file and the malicious DLL onto the system
See also: Corsair: Fake LinkedIn job offers distribute DarkGate malware

The attacker exploits “calc.exe”, which is not just a simple calculator application in this context. When executed, it also activates the malicious DLL, allowing the “QuasarRAT” payload to be injected into the computer.
After penetrating the computer's memory, the malicious payload performs "process hollowing" to integrate itself into a legitimate system process, further concealing its malicious intentions and making detection difficult.
See also: Fake Google Ads promote KeePass and distribute malware
Uptycs emphasizes that to protect yourself from QuasarRAT and its new capabilities, you must do the following:
- Software and systems updates
- Use reliable antivirus programs
- Beware of suspicious emails and attachments
- System Protection: Securing systems is recommended as a first line of defense. It is crucial to secure systems with the latest updates and patches.
- Firewall and IDS/IPS: Installing a hard firewall and an system (IDS/IPS) is essential.
- Training & Awareness: Educating and raising awareness among users against phishing can significantly reduce the risk of infection by QuasarRAT.
Source: www.infosecurity-magazine.com
