<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>QuasarRAT on Alert Overload</title>
    <link>https://alertoverload.com/categories/quasarrat/</link>
    <description>Recent content in QuasarRAT on Alert Overload</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 23 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://alertoverload.com/categories/quasarrat/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Lab: Deploying Ransomware via QuasarRAT and ClickFix</title>
      <link>https://alertoverload.com/posts/2026/08/lab_deploying_ransomware/</link>
      <pubDate>Sun, 23 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://alertoverload.com/posts/2026/08/lab_deploying_ransomware/</guid>
      <description>&lt;h1 id=&#34;lab-deploying-ransomware-via-quasarrat-and-clickfix&#34;&gt;Lab: Deploying Ransomware via QuasarRAT and ClickFix&lt;/h1&gt;&#xA;&lt;p&gt;SKIP TO LAB MATERIALS IF YOU WANT TO DO THIS BLIND&#xA;&lt;a href=&#34;#materials&#34;&gt;Questions and lab material can be found here.&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;scenario&#34;&gt;Scenario&lt;/h2&gt;&#xA;&lt;p&gt;An employee at Bajiri Corp has logged into their computer and found that none of their files can open and that there is a ransom note on the desktop. The IT team was able to scope out the incident to the device and have taken a memory capture, used KAPE to gather evidence, and has also provided the elastic logs for what they believe is the incident scope.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
