Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

New QuimaRAT malware targets Windows, Linux, and macOS via MaaS model

A new cross-platform remote access trojan named QuimaRAT, distributed via a Malware-as-a-Service model, targets Windows, Linux, and macOS systems using a Java-based payload delivered through multiple executable formats. The malware employs a modular architecture for dynamic plugin delivery via its C2 infrastructure and establishes persistence through OS-specific mechanisms like Registry Run keys, cron jobs, and LaunchAgents. It provides attackers with extensive capabilities including credential theft, file transfer, and remote surveillance.
Read Full Article →

Malware New QuimaRAT malware targets Windows, Linux, and macOS via MaaS model July 7, 2026 Share By SC Staff A new Java-based remote access trojan (RAT) named QuimaRAT has been identified by LevelBlue, capable of infecting Windows, Linux, and macOS systems. This cross-platform malware is being offered as a malware-as-a-service (MaaS), with subscription costs ranging from $150 for one month to $1,200 for lifetime access, according to a recent report by The Hacker News. QuimaRAT features a modular architecture, allowing for dynamic expansion of capabilities through encrypted plugins delivered via its command-and-control (C2) infrastructure. The associated builder supports multiple output formats including JAR, EXE, APP, SH, BAT, and VBS, enabling tailored packaging for different environments. While promising stealth on Windows and Linux, macOS users may need to have admin permissions for certain features. The malware suite also includes a builder, loader, and dropper. QuimaRAT employs various persistence methods, such as Registry Run keys, Scheduled tasks, Startup folder on Windows, .desktop autostart entries and crontab on Linux, and LaunchAgent plist files on macOS. It can execute commands remotely, steal credentials, transfer files, manipulate the clipboard, and conduct webcam surveillance, offering attackers extensive control over compromised systems. Source: The Hacker News SC Staff Related Malware Attackers use Microsoft Teams voice calls to deliver EtherRAT malware SC Staff July 7, 2026 The campaign, detailed by Palo Alto Networks' Unit 42, begins with a phishing email containing a malicious PDF. Malware New ChocoPoC trojan targets security researchers with fake exploit code SC Staff July 2, 2026 ChocoPoC operates by hiding its malicious payload within a Python package that is pulled in as a dependency by the seemingly harmless PoC code. Malware Critical Langflow vulnerability exploited to deploy Monero cryptocurrency miner SC Staff July 2, 2026 The attack chain begins with a single line of Python code executed via an unauthenticated Langflow API endpoint. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article