[GH-ISSUE #389] Builder: attempt to bind the client to a common windows process #186

Closed
opened 2026-02-27 15:49:15 +03:00 by kerem · 4 comments
Owner

Originally created by @webiummedia on GitHub (Sep 9, 2015).
Original GitHub issue: https://github.com/quasar/Quasar/issues/389

I seen this in an other rat. In the builder you could tick a box where on installation the client would try to bind itself to an existing windows process so it can't be killed by the user or makes it look legit when the task manager is checked.

Originally created by @webiummedia on GitHub (Sep 9, 2015). Original GitHub issue: https://github.com/quasar/Quasar/issues/389 I seen this in an other rat. In the builder you could tick a box where on installation the client would try to bind itself to an existing windows process so it can't be killed by the user or makes it look legit when the task manager is checked.
kerem 2026-02-27 15:49:15 +03:00
  • closed this issue
  • added the
    wont-add
    label
Author
Owner

@yankejustin commented on GitHub (Sep 9, 2015):

I don't like this idea. This is almost entirely for malicious purposes which we are moving away from.

<!-- gh-comment-id:139063174 --> @yankejustin commented on GitHub (Sep 9, 2015): I don't like this idea. This is almost entirely for malicious purposes which we are moving away from.
Author
Owner

@webiummedia commented on GitHub (Sep 10, 2015):

Actually this can be useful when an employee is under investigation by the administration like I am doing now.

<!-- gh-comment-id:139089622 --> @webiummedia commented on GitHub (Sep 10, 2015): Actually this can be useful when an employee is under investigation by the administration like I am doing now.
Author
Owner

@yankejustin commented on GitHub (Sep 10, 2015):

I see your use of it but this really hits the realm of process injection at an angle that couldn't make it easier to exploit. 🎩

<!-- gh-comment-id:139107919 --> @yankejustin commented on GitHub (Sep 10, 2015): I see your use of it but this really hits the realm of process injection at an angle that couldn't make it easier to exploit. :tophat:
Author
Owner

@MaxXor commented on GitHub (Sep 10, 2015):

No.

<!-- gh-comment-id:139143073 --> @MaxXor commented on GitHub (Sep 10, 2015): No.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/Quasar#186
No description provided.