
QuasarRAT Toolkit Recompiled for 13 Years Gains a Crypto Clipper
Four newly-flagged Windows binaries tied to the LazyScripter cluster trace back to the same QuasarRAT-derived chassis first compiled in 2011 and still shipping in September 2024. The only real change across that span is a clipboard-hijacking wallet-swap module bolted onto the same RDPWrap-persistent, Vermin/xRAT-laced code.
Four newly-flagged Windows binaries tied to a cluster the upstream feed labels LazyScripter share an unbroken thread: the same QuasarRAT-derived toolkit fingerprint, first compiled in 2011 and still shipping in September 2024, with a clipboard-hijacking wallet-swap module now bolted onto the frame. Rather than a fresh malware family, what CTX Team's review of the sample set shows is a chassis — Quasar's remote-access core, wrapped in RDP-wrapper persistence and Vermin/xRAT keylogging code —…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read