Threat reportMalwareTL-2026-2397
QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service
QuimaRAT v2.0 (TL-2026-2397), also tracked as QuimaRAT v2.0, is a high-severity malware campaign, first published 2026-09-08. It has no confirmed attribution, affects Oracle Java Runtime Environment, maps to 17 MITRE ATT&CK techniques (T1008, T1027, T1036), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-2397
- Threat ID
- TL-2026-2397
- Also known as
- QuimaRAT v2.0, SWFT
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- technology, finance, government administration, health, critical-infrastructure
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in QuimaRAT v2.0
Malware and tooling: Quima Builder, Quima Dropper, Quima Loader
How QuimaRAT v2.0 works
QuimaRAT is a Java-based cross-platform Remote Access Trojan (RAT) marketed as Malware-as-a-Service (MaaS) on dark web forums. Built with Apache Maven and running on Java SE 8+ JVM, it features a modular plugin architecture with AES-256 encrypted C2 communication, repeating-key XOR obfuscated configuration, and embedded JNA native libraries enabling execution across Windows, Linux, and macOS. The full MaaS ecosystem includes a builder generating payloads in 12+ formats (JAR, EXE, APP, SH, BAT, VBS, XLL, LNK, DOCM, MSC, CPL, CHM), a browser-cache loader using fake CAPTCHA lures, an HTML/SVG dropper, and a GUI control panel. Priced from $150/month to $1,200 lifetime access, it is sold by the alias 'nethoodus' on Hack Forums under Telegram handle @QuimaCODER.
QuimaRAT is a commercially marketed cross-platform remote access trojan developed in Java and offered as a Malware-as-a-Service (MaaS) subscription. First publicly documented by LevelBlue SpiderLabs (researchers Chen Aviani and Nikita Kazymirskyi) in June 2026, the malware is sold on Hack Forums by the user 'nethoodus' with Telegram contact @QuimaCODER. The product is branded as QuimaRAT v2.0 and advertised with claims of 70+ modules, AES-256 encryption, FUD (Fully Undetectable) status on Windows and Linux, and a GUI control panel with HVNC capability.
The RAT is built as an Apache Maven project using Netty (asynchronous networking framework with NioEventLoopGroup and thread factory 'quima-nio') and Gson for JSON serialization. It targets Java SE 8, 11, 17, and 21 runtimes and embeds JNA (Java Native Access) native libraries for Windows (x86, x86-64, ARM), Linux (x86, x86-64, ARM), and macOS to perform low-level OS operations across all three platforms. The JAR archive contains an encrypted config.dat file protected with repeating-key XOR using the hardcoded key 'QuimaRAT20'. Decrypted configuration fields include targetOs, hosts (C2 IP/port list), serverId (campaign identifier), transport protocol, SSL toggle, persistence toggles, anti-VM checks, reconnection delay, pastebin-based C2 rotation URL, binder options, and certificate pinning hash.
QuimaRAT implements 23 confirmed commands in its base JAR client within a broader protocol supporting 235 commands (212 additional protocol-only commands deliverable via encrypted plugins). Confirmed capabilities include in-memory shellcode execution via SEND_FILELESS_EXECUTE (using JNA Kernel32 calls: VirtualAlloc, VirtualProtect, CreateThread), remote file download and execution (DOWNLOAD_EXECUTE extracting URLs from C2 packets, SEND_FILE_EXECUTE delivering binary payloads directly in C2 packets), file transfer, clipboard manipulation, screen capture, keylogging, remote command execution, process enumeration, and system information gathering. The C2 protocol uses HANDSHAKE and HEARTBEAT commands for session lifecycle management.
The builder/generator component, Quima Builder, supports multiple output formats: JAR, EXE, APP, SH, BAT, VBS, XLL (Excel add-in), LNK (shortcut), JS, DOCM, XLSM, MSC (Microsoft Management Console), CPL (Control Panel), and CHM (Compiled HTML Help). The Quima Loader employs a browser-cache delivery technique: victims land on fake CAPTCHA or software update landing pages that silently store the JAR payload in browser cache. A secondary lightweight loader binary then retrieves and executes the cached payload locally — no download dialog, no suspicious file extension. The Quima Dropper generates HTML/SVG-based payloads for initial delivery.
Persistence mechanisms are OS-aware: on Windows, the malware copies itself to %APPDATA% and installs Registry Run keys, Scheduled Tasks, and Startup folder entries. On Linux, it creates ~/.config/autostart/iGmcYueWny.desktop entries and @reboot cron jobs. On macOS, it installs a LaunchAgent plist at ~/Library/LaunchAgents/com.igmcyuewny.plist with KeepAlive: true. Anti-analysis features include OS-specific virtualization detection (checking for vboxservice.exe, vmtoolsd.exe, qemu-ga.exe on Windows; sysctl -n hw.model on macOS), single-instance enforcement via Java FileLock on a .lock file in the OS temp directory, ProGuard obfuscation with Maven Shade package relocation, and no visible UI elements. The malware queries external IP geolocation services (ipinfo.io/ip, api.ipify.org, checkip.amazonaws.com, ip-api.com) for environment awareness.
C2 infrastructure uses configurable transport modes including TCP, SSL, HTTP, and HTTPS. The analyzed sample communicated over plain TCP to 45.63.24.218:4447 (domain: quima.org) with campaign identifier 'MONDAY 1'. A Pastebin-based C2 host rotation mechanism allows operators to update C2 addresses dynamically by fetching lines formatted as IP:PORT:TRANSPORT from a configurable pastebinUrl. If retrieval fails, the RAT falls back to statically configured hosts. The reconnection interval uses a randomized delay via ThreadLocalRandom.current().nextLong() with a fallback reconnect thread.
While no specific advanced persistent threat (APT) group has been attributed to QuimaRAT, its MaaS model and commercial distribution on cybercrime forums lower the barrier to entry for a wide range of threat actors. Enterprise Java environments (Spring Boot, Kafka, Hadoop, Android build systems) represent high-value targets because they require JREs by definition. The analyzed sample (SHA-256: bb0fbcb1e47ec04aa55555f3769fbc6f09694de1e9baae59260356b26b5af6a7, 3.59 MB, named SWFT.jar) was documented in the LevelBlue threat spotlight report. Broadcom/Symantec published a protection bulletin on July 3, 2026.
MITRE ATT&CK techniques used in TL-2026-2397
Command and Control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1095 Non-Application Layer Protocol; T1573 Encrypted Channel
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Credential Access
Execution
T1059 Command and Scripting Interpreter; T1106 Native API
Discovery
T1082 System Information Discovery
Collection
execution
Initial Access
Affected products and versions in QuimaRAT v2.0
- Oracle — Java Runtime Environment
Vulnerable versions: 8; 11; 17; 21 - Microsoft — Windows
Vulnerable versions: 10; 11; Server 2019; Server 2022 - Apple — macOS
Vulnerable versions: Ventura; Sonoma; Sequoia - Linux (multiple distributions) — Linux Desktop
Vulnerable versions: All distributions with JRE installed
Remediation for QuimaRAT v2.0
Patches
- Ensure Java Runtime Environment is kept updated to latest versions (JRE 8u421+, 11 LTS, 17 LTS, or 21 LTS)
- Deploy endpoint protection from vendors with QuimaRAT signatures (Broadcom/Symantec, other major EDR vendors)
Immediate actions
- Block C2 IP 45.63.24.218 and domain quima.org at network perimeter
- Deploy EDR rules to detect long-running Java processes with -cp pointing to %TEMP% or /tmp
- Block outbound TCP on port 4447 from non-whitelisted hosts
- Inspect endpoints for qr_<hash>.lock files in temp directories as infection indicator
- Search for suspicious persistence entries: Registry Run keys, Scheduled Tasks, LaunchAgent plists, .desktop autostart files created by Java processes
Workarounds
- Restrict Java execution to signed and trusted applications on endpoints
- Block Java Web Start and untrusted JAR execution where possible
- Implement application control policies to prevent Java from executing from %TEMP%, /tmp, and browser cache directories
Longer-term hardening
- Implement behavioral detection for Java-based RAT activities including JNA/Kernel32 shellcode execution patterns
- Deploy network monitoring for Netty NioEventLoopGroup connection patterns to unknown IPs
- Monitor for HTTP requests to ipinfo.io/ip, api.ipify.org, checkip.amazonaws.com, ip-api.com as C2 reconnaissance indicators
- Establish detection for Pastebin HTTP requests from Java processes (C2 rotation signal)
- Implement file integrity monitoring on Startup folders, LaunchAgents directories, and .config/autostart
- Apply application allowlisting to restrict untrusted Java execution
Timeline of QuimaRAT v2.0
- Analyzed QuimaRAT sample (SHA-256: bb0fbcb1e47ec04aa55555f3769fbc6f09694de1e9baae59260356b26b5af6a7, 3.59 MB, named SWFT.jar) communicates over plain TCP to C2 infrastructure at 45.63.24.218:4447 under campaign identifier 'MONDAY 1'
- QuimaRAT v2.0 first advertised on Hack Forums by user 'nethoodus' (Telegram @QuimaCODER) with MaaS pricing of $150/month to $1,200/lifetime, claiming 70+ modules, AES-256 encryption, FUD status, and GUI control panel
- LevelBlue SpiderLabs (researchers Chen Aviani and Nikita Kazymirskyi) publishes comprehensive technical analysis of QuimaRAT, documenting modular Maven architecture, XOR-encrypted config.dat (key 'QuimaRAT20'), Netty-based C2 communication, JNA cross-platform support, and 235-command protocol
- Broadcom/Symantec publishes protection bulletin for QuimaRAT with detection signatures for associated malware components
- The Hacker News (Ravie Lakshmanan) publishes article on QuimaRAT, detailing MaaS pricing, cross-platform targeting, builder/loader/dropper ecosystem, and Pastebin-based C2 rotation mechanism
- Independent security analysts (byteiota, threat.wiki, CraftedSignal) publish additional analyses covering MITRE ATT&CK mappings, detailed IOC extraction, and behavioral detection guidance
- Intel 471 publishes emerging threat blog post on QuimaRAT, categorizing it as a Java-based cross-platform RAT MaaS with modular architecture and encrypted plugin delivery
Sources cited for QuimaRAT v2.0
- LevelBlue SpiderLabs — Threat Spotlight: An In-Depth Analysis of QuimaRAT (Full PDF)
- LevelBlue Blog — Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux
- Intel 471 Blog — Emerging Threat: QuimaRAT
- The Hacker News — New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
- Broadcom/Symantec — QuimaRAT Protection Bulletin
- byteiota — QuimaRAT: Java's Cross-Platform Promise Turned Into a $150 Attack Kit
- threat.wiki — QuimaRAT Entry
- CraftedSignal Threat Feed — Emerging Threat: QuimaRAT
Detection coverage for TL-2026-2397
As of 2026-09-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2397 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.