# QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service

> QuimaRAT is a Java-based cross-platform Remote Access Trojan (RAT) marketed as Malware-as-a-Service (MaaS) on dark web forums. Built with Apache Maven and running on Java SE 8+ JVM, it features a modular plugin architecture with AES-256 encrypted C2 communication, repeating-key XOR obfuscated configuration, and embedded JNA native libraries enabling execution across Windows, Linux, and macOS. The full MaaS ecosystem includes a builder generating payloads in 12+ formats (JAR, EXE, APP, SH, BAT, VBS, XLL, LNK, DOCM, MSC, CPL, CHM), a browser-cache loader using fake CAPTCHA lures, an HTML/SVG dropper, and a GUI control panel. Priced from $150/month to $1,200 lifetime access, it is sold by the alias 'nethoodus' on Hack Forums under Telegram handle @QuimaCODER.

- **Published:** 2026-09-08T00:00:00Z
- **Last reviewed:** 2026-09-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2397
- **ID:** TL-2026-2397
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

QuimaRAT is a commercially marketed cross-platform remote access trojan developed in Java and offered as a Malware-as-a-Service (MaaS) subscription. First publicly documented by LevelBlue SpiderLabs (researchers Chen Aviani and Nikita Kazymirskyi) in June 2026, the malware is sold on Hack Forums by the user 'nethoodus' with Telegram contact @QuimaCODER. The product is branded as QuimaRAT v2.0 and advertised with claims of 70+ modules, AES-256 encryption, FUD (Fully Undetectable) status on Windows and Linux, and a GUI control panel with HVNC capability.

The RAT is built as an Apache Maven project using Netty (asynchronous networking framework with NioEventLoopGroup and thread factory 'quima-nio') and Gson for JSON serialization. It targets Java SE 8, 11, 17, and 21 runtimes and embeds JNA (Java Native Access) native libraries for Windows (x86, x86-64, ARM), Linux (x86, x86-64, ARM), and macOS to perform low-level OS operations across all three platforms. The JAR archive contains an encrypted config.dat file protected with repeating-key XOR using the hardcoded key 'QuimaRAT20'. Decrypted configuration fields include targetOs, hosts (C2 IP/port list), serverId (campaign identifier), transport protocol, SSL toggle, persistence toggles, anti-VM checks, reconnection delay, pastebin-based C2 rotation URL, binder options, and certificate pinning hash.

QuimaRAT implements 23 confirmed commands in its base JAR client within a broader protocol supporting 235 commands (212 additional protocol-only commands deliverable via encrypted plugins). Confirmed capabilities include in-memory shellcode execution via SEND_FILELESS_EXECUTE (using JNA Kernel32 calls: VirtualAlloc, VirtualProtect, CreateThread), remote file download and execution (DOWNLOAD_EXECUTE extracting URLs from C2 packets, SEND_FILE_EXECUTE delivering binary payloads directly in C2 packets), file transfer, clipboard manipulation, screen capture, keylogging, remote command execution, process enumeration, and system information gathering. The C2 protocol uses HANDSHAKE and HEARTBEAT commands for session lifecycle management.

The builder/generator component, Quima Builder, supports multiple output formats: JAR, EXE, APP, SH, BAT, VBS, XLL (Excel add-in), LNK (shortcut), JS, DOCM, XLSM, MSC (Microsoft Management Console), CPL (Control Panel), and CHM (Compiled HTML Help). The Quima Loader employs a browser-cache delivery technique: victims land on fake CAPTCHA or software update landing pages that silently store the JAR payload in browser cache. A secondary lightweight loader binary then retrieves and executes the cached payload locally — no download dialog, no suspicious file extension. The Quima Dropper generates HTML/SVG-based payloads for initial delivery.

Persistence mechanisms are OS-aware: on Windows, the malware copies itself to %APPDATA% and installs Registry Run keys, Scheduled Tasks, and Startup folder entries. On Linux, it creates ~/.config/autostart/iGmcYueWny.desktop entries and @reboot cron jobs. On macOS, it installs a LaunchAgent plist at ~/Library/LaunchAgents/com.igmcyuewny.plist with KeepAlive: true. Anti-analysis features include OS-specific virtualization detection (checking for vboxservice.exe, vmtoolsd.exe, qemu-ga.exe on Windows; sysctl -n hw.model on macOS), single-instance enforcement via Java FileLock on a .lock file in the OS temp directory, ProGuard obfuscation with Maven Shade package relocation, and no visible UI elements. The malware queries external IP geolocation services (ipinfo.io/ip, api.ipify.org, checkip.amazonaws.com, ip-api.com) for environment awareness.

C2 infrastructure uses configurable transport modes including TCP, SSL, HTTP, and HTTPS. The analyzed sample communicated over plain TCP to 45.63.24.218:4447 (domain: quima.org) with campaign identifier 'MONDAY 1'. A Pastebin-based C2 host rotation mechanism allows operators to update C2 addresses dynamically by fetching lines formatted as IP:PORT:TRANSPORT from a configurable pastebinUrl. If retrieval fails, the RAT falls back to statically configured hosts. The reconnection interval uses a randomized delay via ThreadLocalRandom.current().nextLong() with a fallback reconnect thread.

While no specific advanced persistent threat (APT) group has been attributed to QuimaRAT, its MaaS model and commercial distribution on cybercrime forums lower the barrier to entry for a wide range of threat actors. Enterprise Java environments (Spring Boot, Kafka, Hadoop, Android build systems) represent high-value targets because they require JREs by definition. The analyzed sample (SHA-256: bb0fbcb1e47ec04aa55555f3769fbc6f09694de1e9baae59260356b26b5af6a7, 3.59 MB, named SWFT.jar) was documented in the LevelBlue threat spotlight report. Broadcom/Symantec published a protection bulletin on July 3, 2026.

## MITRE ATT&CK

- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1547 Boot or Logon Autostart Execution
- T1053 Scheduled Task/Job
- T1027 Obfuscated Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1056 Input Capture
- T1082 System Information Discovery
- T1113 Screen Capture
- T1071 Application Layer Protocol
- T1095 Non-Application Layer Protocol
- T1573 Encrypted Channel
- T1008 Fallback Channels

## Sources

- [LevelBlue SpiderLabs — Threat Spotlight: An In-Depth Analysis of QuimaRAT (Full PDF)](https://www.levelblue.com/hubfs/Web/Library/Documents_pdf/Threat_Spotlight_An_In_Depth_Analysis_of_QuimaRAT.pdf)
- [LevelBlue Blog — Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux](https://www.levelblue.com/blogs/spiderlabs-blog/novel-java-based-quimarat-targets-windows-macos-and-linux)
- [Intel 471 Blog — Emerging Threat: QuimaRAT](https://www.intel471.com/blog/emerging-threat-quimarat)
- [The Hacker News — New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS](https://thehackernews.com/2026/07/new-java-based-quimarat-maas-built-to.html)
- [Broadcom/Symantec — QuimaRAT Protection Bulletin](https://www.broadcom.com/support/security-center/protection-bulletin/quimarat-cross-platform-remote-access)
- [byteiota — QuimaRAT: Java's Cross-Platform Promise Turned Into a $150 Attack Kit](https://byteiota.com/quimarat-javas-cross-platform-promise-turned-into-a-150-attack-kit/)
- [threat.wiki — QuimaRAT Entry](https://threat.wiki/tools/quimarat/)
- [CraftedSignal Threat Feed — Emerging Threat: QuimaRAT](https://craftedsignal.com/threat-feed/quimarat)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2397
