DILLWEED

Description

(Cylance) QuasarRAT is a lightweight remote administration tool written in C#. It can collect system information, download and execute applications, upload files, log keystrokes, grab screenshots/camera captures, retrieve system passwords and run shell commands. The remote access Trojan (RAT) is loaded by a bespoke loader (a.k.a. DILLWEED). The encrypted QuasarRAT payload is stored in the Microsoft.NET directory, decrypted into memory, and instantiated using a CLR host application. In later variants an additional component is also used to install the RAT as a service (a.k.a DILLJUICE).

Names

Name
DILLWEED

Category

Malware

Type

  • Loader

Information

Other Information

Uuid

6b35dce4-3aa4-4754-8bd1-27f6a77fc395

Last Card Change

2020-04-20