Cybersecurity researchers have discovered a new Java-based remote access trojan (RAT) called QuimaRAT that is designed to infect Windows, Linux, and macOS systems. The malware stands out because it is written in Java, allowing attackers to use the same malicious code across multiple operating systems. Researchers found that QuimaRAT is being sold as a Malware-as-a-Service (MaaS), making it easier for cybercriminals to launch attacks without creating their own malware. This business model lowers the barrier for attackers and increases the risk for organizations worldwide.

According to researchers, QuimaRAT is available through different subscription plans, with prices starting at $150 for one month and going up to $1,200 for lifetime access. Other plans include three months for $300, six months for $500, and one year for $700. Customers who purchase the malware receive access to a complete toolkit instead of just the malware itself. This package allows threat actors to create, customize, and manage attacks more efficiently.
The QuimaRAT toolkit includes four major components known as Quima Control, Quima Builder, Quima Loader, and Quima Dropper. Quima Control acts as the main remote access trojan, while Quima Builder helps attackers create customized malware samples. The Loader is responsible for delivering the malware onto targeted systems, and the Dropper assists in installing the infection. Together, these tools provide attackers with a complete platform for carrying out cyberattacks.

Researchers also found that QuimaRAT follows a modular design, allowing attackers to expand its capabilities through encrypted plugins delivered from its command-and-control server. This approach enables cybercriminals to add new features without replacing the entire malware. The modular architecture also makes the malware more flexible, helping it adapt to different attack scenarios. Such a design increases its long-term usefulness for threat actors.
One of the most notable techniques used by QuimaRAT involves its Loader component, which stores a malicious file inside a browser’s cache. When a victim opens a specially generated link, the loader is placed in the cache instead of being downloaded in a traditional way. Researchers say this method is designed to bypass Windows SmartScreen protections, making the attack less likely to be blocked during the early stages. This delivery technique highlights the growing sophistication of modern malware campaigns.

Once installed, QuimaRAT provides attackers with remote access to compromised devices. This access can allow cybercriminals to execute commands, collect sensitive information, download additional malware, and maintain long-term control over infected systems. Because it supports Windows, Linux, and macOS, the malware poses a broader threat than many platform-specific remote access trojans. Organizations using multiple operating systems may therefore face increased exposure.
Security researchers warn that QuimaRAT’s cross-platform support, modular structure, and subscription-based distribution model make it a significant threat for businesses and individuals alike. The availability of ready-made malware services allows less experienced attackers to conduct advanced campaigns with minimal technical knowledge. As Malware-as-a-Service continues to grow, similar threats are expected to become more common across different industries.

Experts recommend that organizations closely monitor Java-related processes, unusual browser cache activity, and unexpected file execution on endpoints. Strong endpoint detection and response solutions, regular system updates, network segmentation, and careful monitoring of suspicious behavior can help reduce the risk of infection. Researchers believe that understanding how threats like QuimaRAT operate is essential for improving cyber defenses as malware continues to evolve across multiple operating systems.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news