Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Pulsar RAT

41
Global rank
70 infographic chevron month
Month rank
57
Week rank
0
IOCs

Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.

RAT
Type
Unknown
Origin
1 April, 2025
First seen
19 August, 2026
Last seen

How to analyze Pulsar RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 April, 2025
First seen
19 August, 2026
Last seen

IOCs

IP addresses
52.110.17.51
95.100.102.9
150.171.28.11
23.11.41.157
95.100.102.101
23.52.181.212
140.82.121.3
2.16.168.44
185.199.109.133
150.171.109.34
40.126.31.1
48.192.1.64
23.197.142.186
140.82.113.21
150.171.22.17
184.24.77.35
185.199.108.215
172.211.123.249
20.165.94.63
48.209.6.48
Hashes
0e60b52689f3627486b9a77bb4f88bea0d8665a94f7f1ffc960a1fbc427626b7
accccfbe45d9f08ffeed9916e37b33e98c65be012cfff6e7fa7b67210ce1fefb
e905d102585b22c6df04f219af5cbdbfa7bc165979e9788b62df6dcc165e10f4
bf3fb84664f4097f1a8a9bc71a51dcf8cf1a905d4080a4d290da1730866e856f
d126884d48a4d27e8048590fa9f3c9c1df699b825b69cfe086d769d898289dda
c3ae599b5218516915f6542779ef577d5ad5de3d84a116e671c09e15e4591285
aced52254a8c3cb6ad30f99f8b745296926c49373cab00824c2c4c10ad325b10
2ae73e12cb1e9989929920c4e9da0b02b6f6f8f0bd1944ac9ebfbf6b4dca746b
c4494b603ecb322627959b2cd782400405a58051229bd09b108861415b1845aa
3a4ed9b3e4b5d706767ef614b52836250e8abfadb7b8e30e3706c2eb9d1c45e3
8232c450f967d7f2f22c54582f0667f4c033ae62e6d450ff8a35c47486249443
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
f51a7acfffec56d6751561966d947d3fd199b74528c07dabdcf5fcb33d5b2e85
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
88301f0b7e96132a2699a8bce47d120855c7f0a37054540019e3204d6bcbaba3
138e49660d259061d8152137abd8829acdfb78b69179890beb489fe3ffe23e0c
c35020473aed1b4642cd726cad727b63fff2824ad68cedd7ffb73c7cbd890479
c3338f7c5cd465788643d4a5d5eb920a8411dbf2a1c9cdc8efa361d277e3ac49
Domains
clients2.googleusercontent.com
edge.microsoft.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
api.github.com
fe3cr.delivery.mp.microsoft.com
update.googleapis.com
config.edge.skype.com
ipwho.is
settings-win.data.microsoft.com
go.microsoft.com
edge-mobile-static.azureedge.net
avatars.githubusercontent.com
self.events.data.microsoft.com
www.bing.com
client.wns.windows.com
slscr.update.microsoft.com
messaging.lifecycle.office.com
login.live.com
raw.githubusercontent.com
copilot.microsoft.com
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:8sjrqda-n7qla4fadfo0ubdqvgkodfcsmvoptkgy9yu&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://github.com/execteam-code/ultimate-rat-collection-fork/tree/main/pulsar/mods/pulsarmodified
https://copilot.microsoft.com/c/api/user/eligibility
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://github.githubassets.com/assets/light-b18a1a7ee7730775.css
https://github.githubassets.com/assets/99836-03e21fa875606c9b.js
https://github.githubassets.com/assets/keyboard-shortcuts-dialog-654bb94339ca7c2f.js
https://github.githubassets.com/assets/4731-2167f29f1bb89be4.js
https://github.githubassets.com/assets/40307-62b0783274b0cb28.js
https://github.githubassets.com/assets/71236-e3cbad5c0244a092.js
https://github.githubassets.com/assets/37403-1d55aee395bb1f70.js
https://github.githubassets.com/assets/48129-b05fdfc09652a401.js
https://github.githubassets.com/assets/24360-58c4d85aef273d16.js
https://github.githubassets.com/assets/43403-0bca3af24d796f03.js
https://github.githubassets.com/assets/lazy-react-partial-marketing-header-b8bc188c7dc81eae.js
https://github.githubassets.com/assets/marketing-header-30bbf764cb5d3f8f.js
https://github.githubassets.com/assets/light_high_contrast-9d093cb5adfc6a5b.css
Last Seen at

Recent blog posts

post image
Hunt Malware & Phishing Threats with ANY....
watchers 807
comments 0
post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 5840
comments 0
post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 12585
comments 0

Pulsar RAT Exposed: Modular Menace with Clipboard Hijacking and Supply Chain Tricks

Key Takeaways

  1. Pulsar RAT is an evolution of Quasar RAT with enhanced stealth, comprehensive surveillance capabilities including webcam and microphone access, and cryptocurrency wallet clipping.
  1. The malware employs advanced evasion techniques including anti-virtualization checks, anti-debugging protections, memory-only execution, and multi-layered obfuscation.
  1. Supply chain attacks represent a growing distribution vector.
  1. Business impact extends far beyond technical compromise with organizations facing intellectual property theft, regulatory violations, operational disruption requiring 200-500 person-hours for remediation, and potential supply chain compromise affecting partners.
  1. Defense requires layered security controls combining EDR platforms, network segmentation, user security awareness training that prevents 60-90% of social engineering attacks.
  1. TI Lookup delivers instant threat intelligence enabling security teams to rapidly search for Pulsar RAT indicators across URLs, domains, and IP addresses, retrieving comprehensive intelligence including sample analysis results, network infrastructure, and campaign data.

destinationIP:"72.230.113.5".

IP detected as Pulsar RAT Suspicious IP detected as Pulsar IOC, plus most targeted sectors and regions

  1. ANY.RUN's Interactive Sandbox provides deep analysis capabilities for security teams investigating suspicious files, enabling manual interaction with samples to trigger specific behaviors and explore malware functionality that automated analysis might miss.

View analysis

Pulsar RAT sample in Interactive Sandbox Pulsar RAT attack chain in ANY.RUN’s Sandbox

What is Pulsar RAT Malware?

Pulsar RAT represents an evolved fork of the popular open-source Quasar RAT, enhancing its predecessor with additional features and improved stealth. Developed as a modular .NET-based tool, it offers comprehensive remote administration capabilities that can be legitimately used for IT management but are frequently abused by cybercriminals for unauthorized access, espionage, and data theft.

Key enhancements include TLS-encrypted communications, hidden virtual network computing (HVNC) for stealthy remote desktop access, reverse proxy support, and a plugin system for customization. It incorporates specialized modules for credential harvesting (known as Kematian Grabber), cryptocurrency clipboard hijacking, and even "FunStuff" features like screen distortions or fake BSOD triggers.

Pulsar stands out for its robust anti-analysis techniques, making it challenging for security tools to detect and analyze. The malware employs robust anti-virtualization and anti-debugging techniques, code injection capabilities, and built-in obfuscation and packing mechanisms specifically designed to evade detection by security solutions. Its modular design allows for seamless plugin additions, enabling operators to customize functionality for specific campaign objectives.

The tool even includes creative modules labeled "FunStuff" that enable operations like GDI effects, blue screen of death triggers, mouse swapping, and taskbar hiding, showcasing versatility that extends beyond conventional remote administration applications.

First observed in the wild around 2025, Pulsar has been deployed in targeted campaigns, including supply chain attacks, demonstrating its adaptability in the hands of threat actors.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Pulsar RAT Victimology

Pulsar RAT primarily targets Windows users and organizations across various sectors. Known incidents, such as the malicious npm package campaign, suggest a focus on software developers and tech-savvy individuals who install third-party libraries. However, as a versatile RAT, it can affect businesses of all sizes, particularly those with remote workforces or weak endpoint security.

Victims often include small-to-medium enterprises lacking advanced EDR solutions, as well as individual users exposed through phishing or malicious downloads. There is no strong evidence of nation-state targeting, but its data theft features make it appealing for financially motivated attackers seeking credentials, cryptocurrencies, or sensitive corporate data.

What Are Examples of the Most Successful Pulsar RAT Attacks?

This RAT is relatively new, so large-scale campaigns are limited, but notable incidents include:

  • 2025 npm Supply Chain Attack: Malicious packages "solders" and "@mediawave/lib" (published by "codewizguru") used extreme obfuscation and steganography to infect developers installing the libraries, achieving hundreds of weekly downloads before detection.

  • Multi-RAT Deployments: Samples linked to open directories dropping Pulsar alongside Quasar, NjRAT, and XWorm, indicating opportunistic or targeted infections.

No massive breaches publicly attributed yet, but its features suggest potential use in credential theft or precursor to ransomware.

How Pulsar RAT Infiltrates and Functions

Initial access typically occurs through social engineering or supply chain compromises:

  • Malicious Downloads: Phishing emails with laced attachments or links.
  • Supply Chain Attacks: Notably, the 2025 "solders" npm package campaign used 7+ layers of obfuscation (Unicode variables, hex encoding, Base64, steganography in PNG images) to deliver the payload automatically via postinstall scripts.
  • Cracked Software or Pirated Tools: Common distribution vector for RATs like this.

Once inside, it persists via startup entries or scheduled tasks but focuses on stealth rather than worm-like spreading. Lateral movement relies on attacker commands (e.g., via proxy).

Pulsar operates via a client-server model. The client (stub) on the victim machine connects to the attacker's C2 server using encrypted channels (TLS).

The malware retrieves C2 configuration from public paste sites like Pastebin, decrypts the configuration using embedded keys to obtain the C2 server IP or domain, then establishes a BCrypt-encrypted connection using the MessagePack binary protocol for command transmission.

The MessagePack binary protocol enables efficient command serialization and deserialization, allowing attackers to send complex instructions and receive detailed responses about system state.

The malware incorporates multiple evasion techniques to avoid detection during security analysis. Anti-virtualization checks inspect disk labels for strings common in virtual machines like "QEMU HARDDISK." If such indicators are present, execution stops immediately, ensuring the payload avoids sandbox analysis tools.

Code injection capabilities allow the malware to execute within legitimate processes, making detection based on process names ineffective.

Advanced deployment methods load the payload directly into memory via .NET reflection without writing files to disk. This fileless approach bypasses disk-based security monitoring and reduces forensic visibility, making incident response significantly more challenging.

The plugin-based design allows operators to load additional functionality without recompiling the core malware. Modules can be added or removed based on specific campaign requirements, target environments, or evolving attacker objectives.

Sandbox Analysis of a Pulsar RAT Sample

ANY.RUN’s Interactive Sandbox overcomes Pulsar’s ant-detection and sandbox-evasion mechanics, exposing the full attack chain. For this RAT, the Sandbox can reveal unpacking routines, persistence mechanisms, network communications, and data exfiltration attempts.

View a Pulsar RAT sample analysis

Pulsar RAT Sandbox analysis Pulsar RAT detonated in the Interactive Sandbox

In this sample, a quite simple BAT file is created (C:\Users\admin\AppData\Local\Temp\28c726a0.bat):

BAT file created at the start of the attack BAT file created at the start of the attack

This file is used for UAC bypassing at the next step. The mechanism works as follows:

First, the DelegateExecute value is cleared in the registry key HKEY_CLASSES_ROOT\ms-settings\Shell\Open\command. This is necessary so that when ms-settings is opened, the system does not use the COM handler specified in the DelegateExecute value. In this case, the handler is taken directly from the (Default) value.

Therefore, the next step writes a malicious command into the (Default) value: this command launches a BAT file and then runs the legitimate program computerdefaults.exe.

The full attack chain proceeds as follows:

Pulsar process succession Pulsar process succession

After the attack executes, the modified registry values are cleared to cover tracks.

The BAT file then launches the executable with elevated privileges. This executable, in turn, creates a scheduled task in Task Scheduler. The task is configured to run at every user logon with HIGHEST privileges.

Malicious file disguised as svchost.exe Malicious file disguised as svchost.exe

This file is a disguised Pulsar RAT, as confirmed by a YARA rule trigger.

Pulsar detected by YARA rule Pulsar detected by YARA rule

After Pulsar finished collecting system information, execution stopped.

Gathering Threat Intelligence on Pulsar RAT Malware

By searching for known Pulsar RAT indicators, security teams retrieve comprehensive intelligence including sample analysis results, network connections, related infrastructure, and historical campaign data. This accelerates investigations by providing immediate context without requiring manual sample collection and analysis.

Start by querying the threat’s name in ANY.RUN’s Threat Intelligence Lookup.

threatName:"pulsar"

Pulsar indicators and targeted industries Pulsar indicators and targeted industries

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Pulsar RAT is a reminder that quiet threats can be the most dangerous. By prioritizing persistence and access, it enables attackers to move patiently, exploit trust, and maximize long-term impact. Organizations that combine proactive detection, sandbox analysis, and high-quality threat intelligence stand the best chance of uncovering and stopping such intrusions early.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Ransomware screenshot
Ransomware
ransomware
Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.
Read More
DoubleTrouble screenshot
DoubleTrouble
doubletrouble
DoubleTrouble is a new-generation Android malware designed to quietly infiltrate mobile devices, harvest sensitive data, hijack financial operations, and maintain long-term persistence. Unlike commodity Android trojans, it blends advanced evasion, dual-stage infection, and dynamic payload updates, making it a rising mobile threat for both consumers and organizations.
Read More
MicroStealer screenshot
MicroStealer
microstealer
MicroStealer is a rapidly emerging infostealer first prominently observed in late 2025. It specializes in stealing browser credentials, active session data, screenshots, cryptocurrency wallets, and system information. It spreads quickly with low detection rates thanks to a sophisticated multi-stage delivery chain and exfiltrates data via Discord webhooks and attacker-controlled servers.
Read More
Salvador Stealer screenshot
Salvador Stealer
salvador
Salvador Stealer is a powerful, information-stealing Android malware designed to silently infiltrate systems, extract sensitive data, and exfiltrate it to cybercriminals. Often sold on underground forums, it is part of the growing ecosystem of “stealers-as-a-service” (SaaS) tools that target individuals and organizations alike.
Read More
GuLoader screenshot
GuLoader
guloader
GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.
Read More
Phorpiex screenshot
Phorpiex
phorpiex
Phorpiex is a malicious software that has been a significant threat in the cybersecurity landscape since 2016. It is a modular malware known for its ability to maintain an extensive botnet. Unlike other botnets, Phorpiex does not concentrate on DDoS attacks. Instead, it has been involved in numerous large-scale spam email campaigns and the distribution of other malicious payloads, such as LockBit.
Read More