Cybersecurity researchers have identified QuimaRAT, a modular, cross-platform remote access trojan sold as a service that targets Windows, Linux, and macOS systems to enable comprehensive remote system control.
Key Points
- QuimaRAT is a Java-based malware suite offered via a subscription model ranging from $150 monthly to $1,200 for lifetime access.
- The toolkit includes a builder, a browser-cache payload delivery service, and an HTML dropper designed to bypass security protections like Windows SmartScreen.
- The malware supports modular expansion through encrypted plugins and utilizes native libraries to interact directly with low-level operating system APIs.
- Attackers can perform credential theft, file transfers, clipboard manipulation, and webcam surveillance once the trojan establishes a command-and-control connection.
- Persistence is achieved through various system-specific methods, including Registry keys on Windows, crontab tasks on Linux, and LaunchAgent files on macOS.