#quasarrat — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #quasarrat, aggregated by home.social.
-
📬 Streaming-Imperium: 7 Millionen Dollar für alte Domains – Malware inklusive
#DarkCommerce #ITSicherheit #abgelaufeneDomains #Cybercrime #Cyberkriminelle #DomainNetzwerke #Dropcatching #illegalesStreaming #Malware #QuasarRAT #SableSquirrel #TrafficDistributionSystem https://sc.tarnkappe.info/dd587c -
💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
In the second part, we unwrap #QuasarRAT, a popular .NET remote access trojan, and show how to extract its encrypted configuration out of the binary.
-
Interesting #OpenDir on #QuasarRat C2 server 185.208.159[.]161:8000 . The open web directory includes source code for a backdoor + misc development artifacts.
https://platform.censys.io/hosts/185.208.159.161
https://search.censys.io/hosts/185.208.159.161 -
Guess we're back to these...:
http://episode-windsor-subdivision-delivery.trycloudflare\.com
https://lol-julian-impossible-bermuda.trycloudflare\.com
https://italia-committees-practical-violence.trycloudflare\.com#asyncrat #purehvnc #quasarrat
jskeywon.duckdns\.org
jbsak.duckdns\.org
jul5050quasae.duckdns\.org
ksj43ts.duckdns\.org -
NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT – Source:hackread.com https://ciso2ciso.com/npm-package-disguised-as-an-ethereum-tool-deploys-quasar-rat-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #SmartContract #CyberAttack #QuasarRAT #Ethereum #Hackread #security #malware #NPM
-
NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT https://hackread.com/npm-package-disguised-ethereum-tool-quasar-rat/ #Cybersecurity #SmartContract #CyberAttack #QuasarRAT #Security #Ethereum #security #Malware #NPM
-
🚨 Alert: Watch out as this new malicious NPM package installs #QuasarRAT instead of scanning for ETH contract vulnerabilities. ⚠️
Read: https://hackread.com/npm-package-disguised-ethereum-tool-quasar-rat/
-
Analyzing a Multi-Stage Malware Attack Targeting Digital Marketing Professionals https://thecyberexpress.com/quasar-rat/ #Vietnamesethreatactor #Vietnamesethreatgroup #TheCyberExpressNews #QuasarRATcampaign #TheCyberExpress #VirtualMachine #FirewallDaily #cybercriminal #DarkWebNews #CyberNews #QuasarRAT #Phishing
-
A new collection of 2 indicators is available for Quasar RAT https://vuldb.com/?actor.quasar_rat #quasarrat #apt #cti #ioc
-
Cisco Talos discloses a new Vietnamese financially-motivated actor dubbed CoralRaider, targeting victims in several Asian and Southeast Asian countries since at least 2023. They focus on stealing victims’ credentials, financial data, and social media accounts, including business and advertisement accounts. Known malware used are a QuasarRAT variant called RotBot, and XClient stealer. TTPs include abusing a legitimate service to host the C2 configuration file and uncommon living-off-the-land binaries (LoLBins), including Windows Forfiles.exe and FoDHelper.exe. IOC provided. 🔗 https://blog.talosintelligence.com/coralraider-targets-socialmedia-accounts/
#CoralRaider #Vietnam #cybercrime #threatintel #IOC #QuasarRAT #RotBot #XClient #LoLBin
-
Significant increases from QuasarRAT, the second most popular remote access trojan associated with botnet C&Cs – get the full list here:
https://info.spamhaus.com/botnet-threat-updates
#QuasarRAT #ThreatIntelligence #Malware #Botnet #Threathunting #SecurityResearch #cybersecurity #blueteam #CyberThreats
-
QuasarRAT Deploys Advanced DLL Side-Loading Technique - https://www.redpacketsecurity.com/quasarrat-deploys-advanced-dll-side-loading-technique/
#threatintel #QuasarRAT #DLL_side-loading #Cybersecurity_threats
-
MITRE, in its explanation of this attack method, notes that adversaries often employ side-loading to conceal their actions within legitimate, trusted, and potentially elevated system or software processes.
#Cybersecurity #Trojan #OpenSource #Malware #QuasarRAT #RAT
https://cybersec84.wordpress.com/2023/10/23/new-quasar-rat-hijacks-dlls-to-avoid-detection/
-
Interesting payload dropped from dhlmissed[.]com, delivering a Telegram bot and #QuasarRAT via SCP (!) 😲 Ever seen that before?
zip 🗜️ -> lnk🔗 -> scp 🖥️ -> hta 📄 -> exe 🪲
SSH (SCP):
[email protected] (185.196.8.30 🇺🇸)LNK (launching CMD.exe to copy HTA from remote SSH server):
👉 https://bazaar.abuse.ch/sample/f152336d161c279526b7909693c8f3fe8775f5c037cf471a41bb22ae0c4b2f85/HTA:
👉 https://bazaar.abuse.ch/sample/ae8c4f72c13b4103e0e977bbf2939a4b97860d1c279994d1b0bd27e00cbf8c2f/Final payloads:
👉 https://bazaar.abuse.ch/sample/c284505447b8529fdd468e13f149582f5083cf442733bfb7bdebf66d38476f20/
👉 https://bazaar.abuse.ch/sample/a7cf48b6108e96096026425b964905f2035427c2af97fca0618d5947515f25b2/Payload URLs:
👉 https://urlhaus.abuse.ch/host/frankmullers.duckdns.org/QuasarRAT #botnet C2 (AZEA GROUP LLC, 🇷🇺):
👉 https://threatfox.abuse.ch/ioc/1188051/ -
Todays #NewsYouShouldKnow included discussion about #QuasarRat being propagated via malicious #OneNote .one files.
I broke down the anatomy of this attack here and offer some free and effective mitigations for #BlueTeam #Defenders to help prevent this #threat
#Infosec #ThreatIntel
https://www.justinmcafee.com/2023/01/malicious-onenote.html -
Небесное око. Тестируем возможности Quasar RAT #rat #quasarrat #guide #подписчикам
https://xakep.ru/2020/10/28/quasar-rat/ https://twitter.com/XakepRU/status/1321385001540268035/photo/1