UAC-0020__2018__VERMIN_Quasar_RAT_and_Custom_Malware_Used_In_Ukraine.pdf
ID: 3ba8b469-bde1-4031-845d-1a1ea0dcf42e
STIX ID: report--3ba8b469-bde1-4031-845d-1a1ea0dcf42e
Threat Score
70/100
Uploaded: 2026-08-19
Published Date: 2018-01-30
Last Modified Date: 2018-01-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
VERMIN:Quasar RAT and Custom Malware Used In Ukraine analyzes a new VERMIN malware family written in .NET, alongside Quasar RAT, linked to a Ukrainian-targeted campaign dating back to 2015. The report details malware behavior (decoy documents, ConfuserEx obfuscation, embedded keylogger, SOAP-based C2, scheduled task persistence), capabilities (collection of host data, keystrokes, clipboard), and a network of C2 infrastructure with multiple IOCs; it also provides sample hashes and appendix data for defenders.
