Threats Tagged 'quasar rat'
View all threats tagged with 'quasar rat'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'quasar rat'
Click on any threat for detailed analysis and mitigation recommendations
Fraudulent organizations in Korea are exploiting private Home Trading System (HTS) software to distribute ransomware to victims. The unauthorized HTS program called 'UBP Asset' impersonates the legitimate Swiss financial institution Union Bancaire Privee (UBP) and has been used in investment scams since at least September 2025. Attackers lure victims through social media platforms like Telegram and KakaoTalk, convincing them to install the fraudulent HTS and deposit funds. The latest campaign involves distributing KRSID ransomware through the HTS update mechanism, which encrypts files using AES-256 and RSA-2048 algorithms. Previous campaigns used similar private HTS programs to distribute Quasar RAT. Victims not only lose their investment funds but also have their systems compromised and files encrypted for ransom demands. Join the discussion | AlienVault OTX General | 09/18/2026, 13:20:16 UTC Added: 09/18/2026, 14:16:39 UTC |
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets. Join the discussion | AlienVault OTX General | 08/13/2026, 16:05:49 UTC Added: 08/14/2026, 10:41:16 UTC |
Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries. Join the discussion | AlienVault OTX General | 07/29/2026, 13:59:47 UTC Added: 07/31/2026, 11:22:21 UTC |
This analysis examines new obfuscation techniques employed by Gremlin stealer malware to conceal malicious payloads within embedded resources. A variant protected by sophisticated commercial packing utility uses instruction virtualization, transforming code into custom bytecode executed by a private virtual machine. The malware siphons sensitive information including payment card details, browser cookies, session tokens, cryptocurrency wallet data, and FTP/VPN credentials from compromised systems. It exfiltrates data to attacker-controlled servers at hxxp[:]194.87.92[.]109 for potential publication or sale. Recent iterations incorporate expanded Discord token extraction, active financial fraud through crypto clipper functionality that replaces cryptocurrency wallet addresses in real-time, and WebSocket-based session hijacking to bypass modern cookie protections. The malware employs advanced anti-analysis techniques including XOR-encoded payloads in .NET resource sections, identifier renaming, string encryp... Join the discussion | AlienVault OTX General | 05/15/2026, 15:23:31 UTC Added: 05/15/2026, 18:51:38 UTC |
A fake website impersonating Avast antivirus is tricking users into infecting their computers with Venom Stealer malware. The site runs a fake virus scan, claims to find threats, and prompts users to download a malicious file disguised as a system cleaner. The malware, identified as part of the Venom Stealer family, steals browser credentials, session cookies, cryptocurrency wallets, and other sensitive data. It uses evasion techniques like direct system calls and debugger checks to avoid detection. The stolen information is exfiltrated to a command-and-control server disguised as an analytics service. This campaign demonstrates a classic scare-and-fix scam, exploiting users' trust in reputable security brands to deliver malware. Join the discussion | AlienVault OTX General | 03/27/2026, 18:42:11 UTC Added: 04/08/2026, 11:05:57 UTC |
A new Epsilon Red ransomware campaign has been discovered targeting users globally through fake ClickFix verification pages. Active since July 2025, the threat actors employ social engineering tactics and impersonate popular platforms like Discord, Twitch, and OnlyFans to trick users into executing malicious .HTA files via ActiveX. This method leads to silent payload downloads and ransomware deployment. The campaign uses a Clickfix-themed malware delivery site, urging victims to visit a secondary page where malicious shell commands are executed. The attackers also impersonate various streaming services and use romance-themed lures. Epsilon Red, first observed in 2021, shows some similarities to REvil ransomware in its ransom note styling but appears distinct in its tactics and infrastructure. Join the discussion | AlienVault OTX General | 07/25/2025, 10:29:02 UTC Added: 07/25/2025, 12:33:10 UTC |
Showing 1 to 6 of 6 results