#QuiteRAT

Malware/Tool

2023-08-24 • Lazarus Group exploits ManageEngine vulnerability to deploy QuiteRAT

QuiteRAT is a Qt-based remote-access trojan deployed by the North Korean Lazarus Group and described as a smaller successor to MagicRAT with overlapping capabilities, including arbitrary command execution. In early 2023, attackers exploited the pre-authentication Zoho ManageEngine ServiceDesk Plus vulnerability CVE-2022-47966 to deliver it, beginning five days after public proof-of-concept code appeared. Reported targets included internet backbone infrastructure and healthcare organizations in Europe and the United States. The campaign reused infrastructure from other Lazarus operations and also deployed CollectionRAT. Use of the Qt framework was reported to complicate human analysis and reduce the reliability of some machine-learning and heuristic detections because that framework is uncommon in malware development.

Tagged Reports

« Back