logo

UAC-0020__2018__VERMIN_Quasar_RAT_and_Custom_Malware_Used_In_Ukraine.pdf

ID: 3ba8b469-bde1-4031-845d-1a1ea0dcf42e

STIX ID: report--3ba8b469-bde1-4031-845d-1a1ea0dcf42e

Threat Score

70/100

Uploaded: 2026-08-19

Published Date: 2018-01-30

Last Modified Date: 2018-01-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
VERMIN:Quasar RAT and Custom Malware Used In Ukraine analyzes a new VERMIN malware family written in .NET, alongside Quasar RAT, linked to a Ukrainian-targeted campaign dating back to 2015. The report details malware behavior (decoy documents, ConfuserEx obfuscation, embedded keylogger, SOAP-based C2, scheduled task persistence), capabilities (collection of host data, keystrokes, clipboard), and a network of C2 infrastructure with multiple IOCs; it also provides sample hashes and appendix data for defenders.