Scworld QuimaRAT Malware Emerges as Cross-Platform Threat via MaaS Model
Article Content
- •QuimaRAT is a cross-platform RAT targeting Windows, macOS, and Linux systems.
- •The malware is sold as a MaaS with subscription prices from $150 to $1,200.
- •It features a modular architecture and various persistence methods for stealth and control.
QuimaRAT, a new Java-based remote access trojan (RAT), has been identified as a significant threat targeting Windows, macOS, and Linux systems. Offered as malware-as-a-service (MaaS), it has subscription costs ranging from $150 per month to $1,200 for lifetime access. The malware features a modular architecture, allowing dynamic expansion through encrypted plugins. It employs various persistence methods across different operating systems, including Registry Run keys for Windows and LaunchAgent plist files for macOS. QuimaRAT can execute commands remotely, steal credentials, transfer files, and conduct webcam surveillance, providing extensive control to attackers. Its builder supports multiple output formats, enhancing its adaptability for different environments. The malware's stealth capabilities are particularly notable on Windows and Linux, while macOS users may require admin permissions for certain features. The threat landscape is evolving with this malware's capabilities, posing risks to a wide range of users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track QuimaRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…