Researchers have identified QuimaRAT, a Java-based remote access trojan sold through a malware-as-a-service (MaaS) model and built to infect Windows, Linux, and macOS systems. The malware is part of a broader Quima toolkit that includes Quima Builder, Quima Loader, and Quima Dropper, enabling operators to generate payloads in formats such as JAR, EXE, APP, SH, BAT, and VBS, stage delivery through browser-cache techniques, and deploy HTML or SVG droppers. Reported pricing ranges from $150 per month to $1,200 for lifetime access, indicating an effort to lower the barrier for affiliates and other threat actors.
QuimaRAT uses a modular architecture with encrypted plugins and flexible command-and-control over TCP, WebSocket, TLS, and HTTPS, with dynamic C2 rotation reportedly supported through Pastebin-based updates. Analysis found persistence mechanisms tailored to each operating system, along with sandbox evasion, single-instance enforcement, optional decoy execution via a Binder function, and Windows fileless shellcode execution. Once deployed, the RAT can remotely execute commands, steal credentials, transfer files, manipulate the clipboard, conduct webcam surveillance, and expand functionality on demand through additional plugins.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
QuimaRAT was identified as a new Java-based remote access trojan offered as malware-as-a-service and designed to target Windows, Linux, and macOS. Reporting described it as a modular platform with builder, loader, and dropper components, encrypted plugins, and capabilities including remote command execution, credential theft, file transfer, clipboard manipulation, and webcam surveillance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.