HomeSecurityQuimaRAT: New Java RAT targets Windows, Linux and macOS

QuimaRAT: New Java RAT Targets Windows, Linux, and macOS

QuimaRAT is a new, highly dangerous Java- based Remote Access Trojan (RAT) that simultaneously targets Windows , Linux , and macOS environments . The malware is distributed as Malware-as-a-Service (MaaS) , offering would-be attackers a full arsenal of tools to distribute and control infected systems. Its architecture and capabilities make it one of the most comprehensive threats to emerge in the cybercrime landscape in recent times .

QuimaRAT Java-based MaaS RAT for Windows Linux macOS

According to analysis by cybersecurity firm LevelBlue, QuimaRAT is organized as a modular Java project built with Apache Maven, and contains built-in Java Native Access (JNA) for Windows, Linux , and macOS across various architectures. The malware decodes and parses an internal configuration file that is necessary for context validation, persistence,and initiating communication with the Command-and-Control (C2). Researchers Chen Aviani and Nikita Kazymirskyi note that the native components allow the RAT to interact directly with low-level operating system APIs via C/C++, suggesting intentional support for broad deployment across multiple platforms.

See also: Trojanized gaming utilities spread Java-based RAT

QuimaRAT: New Java RAT Targets Windows, Linux, and macOS

QuimaRAT: Modular Architecture and MaaS Capabilities

QuimaRAT has 74 modules for Windows and 46 modules for macOS and Linux , and supports dynamic feature expansion via encrypted plugins that can be delivered, loaded, removed, and updated directly from the C2 infrastructure . The full Quima Suite consists of four main tools: Quima Control (also known as QuimaRAT), Quima Builder , Quima Loader , and Quima Dropper . The malware creator also advertises a builder capable of producing multiple output formats, including JAR , EXE , APP , SH , BAT , and VBS , helping customers tailor the payload for different environments and distribution scenarios.

Of particular interest is Quima Loader , which is a browser cache payload delivery service. The operator can upload an EXE file via a special panel, select a delivery format (e.g. HTA or LNK ) and a landing page template — such as a fake CAPTCHA or software update notification. The tool creates a stager link that, when opened by the victim in the browser, initiates a chain of actions: the landing page loads, the payload is retrieved and stored in the browser cache, a download button appears, and once the victim clicks, a “small, clean loader file” trusted by the browser is stored. Finally, the main payload is executed on the system, bypassing Windows SmartScreen protections .

See also: Bloody Wolf expands attacks with Java-based NetSupport RAT

QuimaRAT: Detection Evasion Techniques and Persistence Mechanisms

One of the most alarming features of QuimaRAT is its ability to remain invisible to both antivirus tools and the user. Its creator claims that the suite “uses what Windows” — native execution paths, system-owned resources, and clean outputs — so that AVs don’t detect anything unusual. The vendor guarantees that attackers can remain completely invisible on Windows and Linux, with no visible UI elements or desktop entries. On macOS, some features like screen recording and login auditing require administrator privileges granted by the user.

Windows desktop settings

Before executing, the malware ensures that only one instance of the trojan is running on the infected machine at any given time. It does this by creating a lock file in the operating system’s temporary directory and preventing other processes from using it at the same time. If it detects that another instance of the RAT already holds the lock, it terminates its execution. In addition, QuimaRAT determines the current operating system and uses this information to determine the next action, dynamically adapting its behavior depending on the target environment.

See also: KimJongRAT targets Windows users via infected .hta files

The emergence of QuimaRAT on the threat landscape highlights the growing trend of professionalizing cybercrime through MaaS models . Organizations and users on Windows , Linux , and macOS are urged to keep their systems updated , use Endpoint Detection and Response ( EDR ) solutions, and be especially cautious of suspicious links and requests to execute files from unknown sources. The cross-platform nature of QuimaRAT makes it a threat to a wide range of users and businesses worldwide, according to The Hacker News.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS