Breaking
Live threat feed August 18, 2026 | 05:54 UTC
6426 CVEs This Month
10 Actively Exploited
0 Ransomware Activity
34 Breaches YTD
Threat Investigation Portal
Investigate an IOC in the live graph workspace.
Investigate IOC
Threat Intelligence

New Java-Based QuimaRAT MaaS Targets Windows, Linux, and macOS

New Java-Based QuimaRAT MaaS Targets Windows, Linux, and macOS

Cybersecurity researchers have discovered QuimaRAT, a new remote access trojan written in Java that can operate across Windows, Linux, and macOS platforms. Offered through a malware-as-a-service business model, QuimaRAT subscriptions range in price and grant varying access durations to the malware’s capabilities.

What happened

Security researchers from LevelBlue have identified a novel remote access trojan named QuimaRAT, developed in Java and designed to run on multiple operating systems including Windows, Linux, and macOS. The trojan is distributed as a malware-as-a-service (MaaS), allowing threat actors to rent access to the malware for specific periods ranging from one month to lifetime use.

QuimaRAT's availability across major platforms distinguishes it from many RATs that focus on a single OS, increasing its potential reach. The malware-as-a-service pricing tiers start from $150 for a one-month subscription, scaling up to $1,200 for lifetime access, indicating a commercialized threat model targeting a diverse attacker base.

Why it matters

The emergence of QuimaRAT highlights ongoing trends in cybercrime commoditization, where malware functionality is increasingly offered as a subscription service. By supporting Windows, Linux, and macOS, QuimaRAT widens the attack surface and may impact a broader range of victims, including individuals and organizations using mixed or less commonly targeted environments.

The availability of such cross-platform malware through MaaS lowers the technical barrier for attackers to carry out remote access and control activities, posing operational challenges for defenders who must protect heterogeneous environments.

What security teams should do

Security teams should monitor for indicators of compromise related to QuimaRAT and consider implementing detection capabilities for Java-based threats. Reviewing system behaviors across all three supported operating systems—Windows, Linux, and macOS—is crucial due to the trojan's cross-platform design.

Organizations are advised to maintain up-to-date endpoint protection solutions, ensure robust access controls, and educate users about the risks posed by remote access trojans. Investigating unusual network traffic and suspicious Java application executions may also help in timely identification and mitigation.

Key technical details

QuimaRAT is implemented in Java, enabling it to function on multiple operating systems without requiring separate versions. The modular design typical of remote access trojans likely facilitates remote control, data exfiltration, and persistence mechanisms, although specific capabilities were not detailed.

The malware is offered via a MaaS model with subscription packages priced between $150 for a one-month period to $1,200 for lifetime access, suggesting a commercialized structure that allows attackers to select service durations according to their needs.

Affected organizations/products

QuimaRAT targets Windows, Linux, and macOS users, expanding its reach across a variety of system environments. No specific organizations or sectors have been publicly identified as targets at this time.

Source attribution

https://thehackernews.com/2026/07/new-java-based-quimarat-maas-built-to.html

Thirumala Rao Padilam
Written by
Thirumala Rao Padilam
error: Content is protected !!