Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Pulsar RAT

53
Global rank
80 infographic chevron month
Month rank
190 infographic chevron week
Week rank

Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.

RAT
Type
Unknown
Origin
1 April, 2025
First seen
26 September, 2026
Last seen

How to analyze Pulsar RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 April, 2025
First seen
26 September, 2026
Last seen

IOCs

IP addresses
159.223.110.159
135.233.95.144
48.209.138.168
23.216.77.21
57.153.246.3
128.24.231.65
23.11.41.157
88.221.169.205
23.216.77.37
135.232.92.97
23.59.18.102
88.221.169.152
40.126.31.67
172.211.123.249
2.16.241.205
162.35.105.142
20.190.159.2
48.192.1.64
74.178.240.51
2.23.246.9
Hashes
4b0a27f87114f86dd472e1875a23cb752462e12107f0a3fdbfd0651a8cd0f3ba
a3f7c663787c2a28ec9cef7721cedc83d6bdf75fff5a54745981686c7f355c71
7cba9c8e6f4c5ae9055bb82e2e6a8eb3190596c00b339af47763808eb31aa2d8
9a1e1ec49b372c4ff4baa697b42d950e280c4bcfeac2c9c61378cf2d05543bf0
77a250ed6a58a9308a61a8f767bf087940c81c286cf79c5debc866c21d273898
ff469d8b35a96f50ec51e851b6a2af1fea49885e9240542722eae852cc92171e
6c7f330f4e5b5b3a823cbdcbc337a94e93716b3c649fa87ef1ddeb7d9f1ceda8
cd9d2480cdcfb4affc5bc7a0a43cf840985ddef8f3e2db6947a51c2b7626d97a
bc9f8ebefe5505eb504755f12e4e29f40b4d6ff2662bf519b1d425c66ab16e6b
962ef71a51791fc1173ede0b7fcad72aa825210e238005e64f6fbb5c44de3e20
77a1b5c0d8189b8f9862e1bf4238a070f7202ffc706502410724ad2950e78d55
362efd86a512546438ed6b3f2d4b4c7ea0b40197c14bc0ed9dbb22240ee7a228
99f3754dec345ed71e2bcb337e3cdc58b1a4c02d290d870dc20ccdd1ff543ae1
7497fbdbb98afca4ac455e3a057c59bcdebaf1280e25c94741dc301f05cb53e5
7b9eb3a8af1d12da22604845995982ca99992876a825f3765e053ddb592620ab
1c99489111112d2150db0e18bbd474ff45f78fef80fa0e533dfd9ecfc6a3a480
3a1db3e7321efb30c4aaf0fad5728728c7aadcebbbe91e4272940db1f9a677f9
5f0058de990a9668e5b0ce2273e74e0d5bfdf79f5e6745dc9b8faeb39822a9ad
219be400169e585320c518a50540eda12e3c4f489322c42d56fdad283d07a021
2f79fa6d217978db2c5a7cf297e73e555c2100e86fa5b2cb4c1deffccae353df
Domains
activation-v2.sls.microsoft.com
login.live.com
self.events.data.microsoft.com
ecs.office.com
crl.microsoft.com
client.wns.windows.com
fe3cr.delivery.mp.microsoft.com
nexusrules.officeapps.live.com
google.com
www.microsoft.com
settings-win.data.microsoft.com
bore.pub
ocsp.digicert.com
slscr.update.microsoft.com
go.microsoft.com
51.240.178.74.in-addr.arpa
zero2six1.duckdns.org
dns.msftncsi.com
www.bing.com
ipwho.is
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.3.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.2.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://www.microsoft.com/pkiops/crl/microsoft%20time-stamp%20pca%202010(1).crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1024
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 2815
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10289
comments 0

Pulsar RAT Exposed: Modular Menace with Clipboard Hijacking and Supply Chain Tricks

Key Takeaways

  1. Pulsar RAT is an evolution of Quasar RAT with enhanced stealth, comprehensive surveillance capabilities including webcam and microphone access, and cryptocurrency wallet clipping.
  1. The malware employs advanced evasion techniques including anti-virtualization checks, anti-debugging protections, memory-only execution, and multi-layered obfuscation.
  1. Supply chain attacks represent a growing distribution vector.
  1. Business impact extends far beyond technical compromise with organizations facing intellectual property theft, regulatory violations, operational disruption requiring 200-500 person-hours for remediation, and potential supply chain compromise affecting partners.
  1. Defense requires layered security controls combining EDR platforms, network segmentation, user security awareness training that prevents 60-90% of social engineering attacks.
  1. TI Lookup delivers instant threat intelligence enabling security teams to rapidly search for Pulsar RAT indicators across URLs, domains, and IP addresses, retrieving comprehensive intelligence including sample analysis results, network infrastructure, and campaign data.

destinationIP:"72.230.113.5".

IP detected as Pulsar RAT Suspicious IP detected as Pulsar IOC, plus most targeted sectors and regions

  1. ANY.RUN's Interactive Sandbox provides deep analysis capabilities for security teams investigating suspicious files, enabling manual interaction with samples to trigger specific behaviors and explore malware functionality that automated analysis might miss.

View analysis

Pulsar RAT sample in Interactive Sandbox Pulsar RAT attack chain in ANY.RUN’s Sandbox

What is Pulsar RAT Malware?

Pulsar RAT represents an evolved fork of the popular open-source Quasar RAT, enhancing its predecessor with additional features and improved stealth. Developed as a modular .NET-based tool, it offers comprehensive remote administration capabilities that can be legitimately used for IT management but are frequently abused by cybercriminals for unauthorized access, espionage, and data theft.

Key enhancements include TLS-encrypted communications, hidden virtual network computing (HVNC) for stealthy remote desktop access, reverse proxy support, and a plugin system for customization. It incorporates specialized modules for credential harvesting (known as Kematian Grabber), cryptocurrency clipboard hijacking, and even "FunStuff" features like screen distortions or fake BSOD triggers.

Pulsar stands out for its robust anti-analysis techniques, making it challenging for security tools to detect and analyze. The malware employs robust anti-virtualization and anti-debugging techniques, code injection capabilities, and built-in obfuscation and packing mechanisms specifically designed to evade detection by security solutions. Its modular design allows for seamless plugin additions, enabling operators to customize functionality for specific campaign objectives.

The tool even includes creative modules labeled "FunStuff" that enable operations like GDI effects, blue screen of death triggers, mouse swapping, and taskbar hiding, showcasing versatility that extends beyond conventional remote administration applications.

First observed in the wild around 2025, Pulsar has been deployed in targeted campaigns, including supply chain attacks, demonstrating its adaptability in the hands of threat actors.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Pulsar RAT Victimology

Pulsar RAT primarily targets Windows users and organizations across various sectors. Known incidents, such as the malicious npm package campaign, suggest a focus on software developers and tech-savvy individuals who install third-party libraries. However, as a versatile RAT, it can affect businesses of all sizes, particularly those with remote workforces or weak endpoint security.

Victims often include small-to-medium enterprises lacking advanced EDR solutions, as well as individual users exposed through phishing or malicious downloads. There is no strong evidence of nation-state targeting, but its data theft features make it appealing for financially motivated attackers seeking credentials, cryptocurrencies, or sensitive corporate data.

What Are Examples of the Most Successful Pulsar RAT Attacks?

This RAT is relatively new, so large-scale campaigns are limited, but notable incidents include:

  • 2025 npm Supply Chain Attack: Malicious packages "solders" and "@mediawave/lib" (published by "codewizguru") used extreme obfuscation and steganography to infect developers installing the libraries, achieving hundreds of weekly downloads before detection.

  • Multi-RAT Deployments: Samples linked to open directories dropping Pulsar alongside Quasar, NjRAT, and XWorm, indicating opportunistic or targeted infections.

No massive breaches publicly attributed yet, but its features suggest potential use in credential theft or precursor to ransomware.

How Pulsar RAT Infiltrates and Functions

Initial access typically occurs through social engineering or supply chain compromises:

  • Malicious Downloads: Phishing emails with laced attachments or links.
  • Supply Chain Attacks: Notably, the 2025 "solders" npm package campaign used 7+ layers of obfuscation (Unicode variables, hex encoding, Base64, steganography in PNG images) to deliver the payload automatically via postinstall scripts.
  • Cracked Software or Pirated Tools: Common distribution vector for RATs like this.

Once inside, it persists via startup entries or scheduled tasks but focuses on stealth rather than worm-like spreading. Lateral movement relies on attacker commands (e.g., via proxy).

Pulsar operates via a client-server model. The client (stub) on the victim machine connects to the attacker's C2 server using encrypted channels (TLS).

The malware retrieves C2 configuration from public paste sites like Pastebin, decrypts the configuration using embedded keys to obtain the C2 server IP or domain, then establishes a BCrypt-encrypted connection using the MessagePack binary protocol for command transmission.

The MessagePack binary protocol enables efficient command serialization and deserialization, allowing attackers to send complex instructions and receive detailed responses about system state.

The malware incorporates multiple evasion techniques to avoid detection during security analysis. Anti-virtualization checks inspect disk labels for strings common in virtual machines like "QEMU HARDDISK." If such indicators are present, execution stops immediately, ensuring the payload avoids sandbox analysis tools.

Code injection capabilities allow the malware to execute within legitimate processes, making detection based on process names ineffective.

Advanced deployment methods load the payload directly into memory via .NET reflection without writing files to disk. This fileless approach bypasses disk-based security monitoring and reduces forensic visibility, making incident response significantly more challenging.

The plugin-based design allows operators to load additional functionality without recompiling the core malware. Modules can be added or removed based on specific campaign requirements, target environments, or evolving attacker objectives.

Sandbox Analysis of a Pulsar RAT Sample

ANY.RUN’s Interactive Sandbox overcomes Pulsar’s ant-detection and sandbox-evasion mechanics, exposing the full attack chain. For this RAT, the Sandbox can reveal unpacking routines, persistence mechanisms, network communications, and data exfiltration attempts.

View a Pulsar RAT sample analysis

Pulsar RAT Sandbox analysis Pulsar RAT detonated in the Interactive Sandbox

In this sample, a quite simple BAT file is created (C:\Users\admin\AppData\Local\Temp\28c726a0.bat):

BAT file created at the start of the attack BAT file created at the start of the attack

This file is used for UAC bypassing at the next step. The mechanism works as follows:

First, the DelegateExecute value is cleared in the registry key HKEY_CLASSES_ROOT\ms-settings\Shell\Open\command. This is necessary so that when ms-settings is opened, the system does not use the COM handler specified in the DelegateExecute value. In this case, the handler is taken directly from the (Default) value.

Therefore, the next step writes a malicious command into the (Default) value: this command launches a BAT file and then runs the legitimate program computerdefaults.exe.

The full attack chain proceeds as follows:

Pulsar process succession Pulsar process succession

After the attack executes, the modified registry values are cleared to cover tracks.

The BAT file then launches the executable with elevated privileges. This executable, in turn, creates a scheduled task in Task Scheduler. The task is configured to run at every user logon with HIGHEST privileges.

Malicious file disguised as svchost.exe Malicious file disguised as svchost.exe

This file is a disguised Pulsar RAT, as confirmed by a YARA rule trigger.

Pulsar detected by YARA rule Pulsar detected by YARA rule

After Pulsar finished collecting system information, execution stopped.

Gathering Threat Intelligence on Pulsar RAT Malware

By searching for known Pulsar RAT indicators, security teams retrieve comprehensive intelligence including sample analysis results, network connections, related infrastructure, and historical campaign data. This accelerates investigations by providing immediate context without requiring manual sample collection and analysis.

Start by querying the threat’s name in ANY.RUN’s Threat Intelligence Lookup.

threatName:"pulsar"

Pulsar indicators and targeted industries Pulsar indicators and targeted industries

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Pulsar RAT is a reminder that quiet threats can be the most dangerous. By prioritizing persistence and access, it enables attackers to move patiently, exploit trust, and maximize long-term impact. Organizations that combine proactive detection, sandbox analysis, and high-quality threat intelligence stand the best chance of uncovering and stopping such intrusions early.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

BQTLock screenshot
BQTLock
bqtlock baqiyatlock
BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration. BQTLock encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, demands payment in Monero cryptocurrency, and performs data theft and system reconnaissance.
Read More
Black Basta screenshot
Black Basta
blackbasta
Black Basta is a ransomware-as-a-service operated by Storm-1811. It emerged in 2022 and uses double extortion tactics, encrypting data and stealing it for ransom. The malware often gains access through spear-phishing and uses tools like QakBot and Cobalt Strike. It's known for exploiting system vulnerabilities and using advanced obfuscation techniques.
Read More
Jigsaw screenshot
Jigsaw
jigsaw
The Jigsaw ransomware, initially detected in 2016, encrypts files on compromised systems and requires a ransom payment in Bitcoin. If the ransom is not paid, the malware starts deleting files, increasing the pressure on victims to comply. Its source code is publicly accessible, allowing various threat actors to customize and repurpose the malware for different objectives.
Read More
Lynx screenshot
Lynx
lynx
Lynx is a double extortion ransomware: attackers encrypt important and sensitive data and demand a ransom for decryption simultaneously threatening to publish or sell the data. Active since mid-2024. Among techniques are terminating processes and services, privilege escalation, deleting shadow copies. Distribution by phishing, malvertising, exploiting vulnerabilities.
Read More
Mirage2FA screenshot
Mirage2FA
mirage2fa
Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.
Read More
Overlord RAT screenshot
Overlord RAT
overlord
Overlord RAT is a cross-platform remote access framework with Go-based agents and a TypeScript/Node/Bun server. It supports encrypted WebSocket C2, remote control, persistence, and multiple operating systems, including Windows, Linux, and macOS.
Read More