LIVE · cybersecurity feed
Live wire
malware

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under

zeroday.news · 26d ago

Security researchers have identified a new Java-based remote access trojan (RAT) named QuimaRAT, which is designed to operate across Windows, Linux, and macOS operating systems. This cross-platform capability makes it a versatile tool for attackers targeting a wide range of user environments.

QuimaRAT is being offered as a malware-as-a-service (MaaS), indicating that its developers are likely selling access or the malware itself to other malicious actors. This model can lower the barrier to entry for cybercriminals, allowing less technically sophisticated individuals to deploy advanced threats.

The malware's core functionality includes typical RAT features such as remote command execution, file management, and potentially other capabilities for surveillance and data exfiltration. Its Java foundation allows it to run on any system with a Java Runtime Environment (JRE) installed, contributing to its cross-platform nature.

While the specific details of QuimaRAT's command-and-control (C2) infrastructure and its full range of capabilities are still under investigation, its existence highlights a growing trend of sophisticated, multi-platform malware being developed and distributed through MaaS models.

The cross-platform design means that organizations with diverse operating system deployments are equally vulnerable. This necessitates a security strategy that accounts for threats across all endpoints, regardless of their underlying OS.

The MaaS aspect also suggests a potential for rapid evolution and wider dissemination of the malware, as multiple threat actors could be leveraging the same underlying code. This can make tracking and attribution more challenging for security teams.

Organizations should ensure their endpoint detection and response (EDR) solutions are capable of identifying and mitigating Java-based threats. Maintaining up-to-date Java installations and applying security patches promptly are crucial steps in reducing the attack surface.

Furthermore, robust network monitoring and security awareness training for employees can help detect and prevent the initial infection vectors that QuimaRAT might employ, such as phishing or malicious downloads. The ongoing analysis of QuimaRAT by security researchers is vital for understanding its evolving tactics and developing effective defenses.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.