Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
QuimaRAT employs various persistence methods, such as Registry Run keys, Scheduled tasks... and crontab on Linux...
TTP # T1059.007 — Command and Scripting Interpreter: JavaScript (Execution)
These native components allow the RAT to interact directly with low-level operating system APIs through C/C++ code, indicating intentional support for broad multi-platform deployment.
QuimaRAT employs various persistence methods, such as Registry Run keys, Scheduled tasks... and crontab on Linux...
The malware sets up persistence using a variety of operating system-specific methods: ... and a LaunchAgent plist file for macOS.
QuimaRAT employs various persistence methods, such as Registry Run keys, Scheduled tasks... and crontab on Linux...
The malware sets up persistence using a variety of operating system-specific methods: ... and a LaunchAgent plist file for macOS.
TTP # T1027 — Obfuscated Files or Information (Defense Evasion)
Quima Loader ... allows an operator to upload an EXE file ... The landing page is loaded, and the payload is fetched and held in the browser cache.
Chargement d’un fichier de configuration chiffré config.dat embarqué dans le JAR, déchiffré via une routine XOR à clé répétée
The author behind the Quima suite claims on their website. 'Native execution paths, system-owned resources, clean outputs.' | The main payload gets executed on the system, while bypassing SmartScreen protections on Windows.
The malware supports a wide range of capabilities, including remote command execution, remote payload and plugin delivery, credential theft, persistence, file transfer, clipboard manipulation, and webcam surveillance...
TTP # T1071 — Application Layer Protocol (Command and Control)
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Java-based cross-platform remote access trojan sold as a Malware-as-a-Service offering. It uses a modular Apache Maven/JAR architecture, embedded encrypted configuration, anti-virtualization and anti-analysis checks, OS-specific persistence, and resilient C2 communications using HANDSHAKE and HEARTBEAT commands, with confirmed and extensible command support.
Cross-platform Java-based remote access trojan offered as malware-as-a-service. It uses a modular architecture with encrypted plugins delivered via C2, supports multiple packaging formats, establishes persistence across Windows, Linux, and macOS, and enables remote command execution, credential theft, file transfer, clipboard manipulation, and webcam surveillance.
A novel cross-platform Java-based remote access trojan sold under a malware-as-a-service model. It uses a modular architecture with encrypted plugins, supports persistence across Windows/Linux/macOS, communicates with C2 over TCP/WebSocket/TLS/HTTPS, can rotate C2 via Pastebin, and provides capabilities including remote command execution, payload/plugin delivery, credential theft, file transfer, clipboard manipulation, webcam surveillance, and fileless shellcode execution on Windows.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.