How to remove QuimaRAT malware from the operating system

Trojan

Also Known As: QuimaRAT remote access trojan

Damage level:

Get free scan and check if your device is infected.

Remove it now

To use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

What kind of malware is QuimaRAT?

QuimaRAT is a Java-based Remote Access Trojan (RAT) sold to cybercriminals as a subscription service. This model, known as Malware-as-a-Service (MaaS), allows anyone who pays the fee to deploy the RAT against targets of their choosing.

According to research published by LevelBlue's SpiderLabs team, QuimaRAT targets Windows, macOS, and Linux. It gives operators full remote control over infected devices and can steal passwords, record keystrokes, and access the victim's webcam and microphone.

The malware is marketed as "QuimaRAT v2.0" on dark web forums. On Windows, it runs fully hidden with no visible windows, no system tray icon, and no trace of its activity for the victim to notice.

QuimaRAT malware detections on VirusTotal

QuimaRAT overview

QuimaRAT is built around a modular architecture that allows operators to extend its capabilities through encrypted plugins. It connects to the attacker's command-and-control server via TCP, WebSocket, TLS, or HTTPS, with a watchdog component keeping the connection alive.

The full suite includes four components: Quima Control (the RAT itself), Quima Builder, Quima Loader, and Quima Dropper. The Loader stages payloads through the browser cache, blending in with files the operating system already trusts to avoid detection by security software.

The RAT is written in Java and built using Apache Maven, with operator settings stored in an encrypted configuration file. At startup it checks for sandbox or virtual machine environments and can alter its behavior accordingly, making automated analysis more difficult.

QuimaRAT's capabilities

QuimaRAT ships with over 70 modules for Windows and 44 for macOS and Linux. Core remote-control features include remote desktop access, HVNC (a hidden screen-control channel), webcam and microphone capture, real-time keylogging, and screenshot taking.

A built-in credential-theft module recovers passwords and tokens across more than 14 categories. This covers saved login data from Chrome, Firefox, and similar browsers, along with Discord, Steam, and various cryptocurrency wallets and wallet browser extensions.

Operators can also browse and manage files on the infected system, run commands via a remote shell, view or kill processes, and route traffic through reverse proxy and port-forwarding features.

The malware additionally supports DLL injection and can download and execute additional payloads on demand. It includes a built-in crypto clipper that monitors the clipboard and silently replaces copied cryptocurrency wallet addresses with those belonging to the attacker.

Persistence and defense evasion

QuimaRAT establishes persistence differently on each supported platform. On Windows it writes to Windows Registry Run keys, creates scheduled tasks, and adds entries to startup folders. On Linux it uses crontab reboot tasks and desktop autostart entries. On macOS it installs LaunchAgent plist files.

To hinder detection and removal, the malware can disable Windows Defender and the firewall, and bypass User Account Control. It applies ProGuard obfuscation and AES-256 string encryption to slow down reverse engineering. Operators can also enable a Pastebin-based option for rotating C2 server addresses.

The Quima Builder packages the implant in twelve output formats, including JAR, EXE, APP, SH, BAT, VBS, and native binaries. The same core RAT can therefore be deployed across all three supported platforms with no code changes needed.

QuimaRAT pricing

QuimaRAT is sold on a tiered subscription model. Prices are $150 per month, $300 for three months, $500 for six months, $700 for twelve months, or $1,200 for a lifetime license. It is advertised on dark web cybercriminal forums alongside similar MaaS tools.

Threat Summary:
Name QuimaRAT remote access trojan
Threat Type Remote Access Trojan (RAT), Information Stealer, Clipper, Trojan
Detection Names Avast (Java:Malware-gen [Trj]), Combo Cleaner (Trojan.GenericKD.80016884), ESET-NOD32 (Java/Agent.WL Trojan), Kaspersky (HEUR:Backdoor.Java.Agent.gen), Full List (VirusTotal)
Symptoms Remote Access Trojans are designed to stealthily infiltrate the victim's computer and remain silent, and thus no particular symptoms are clearly visible on an infected machine.
Distribution methods Malicious software installers, phishing emails, social engineering, software 'cracks'.
Damage Stolen passwords and banking information, identity theft, the victim's computer added to a botnet, additional infections, monetary loss, account hijacking.
Malware Removal (Windows)

To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.

Download Combo Cleaner

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Conclusion

QuimaRAT gives cybercriminals a broad toolkit for remote control, credential theft, clipboard hijacking, and further malware deployment. Its stealth design and anti-detection features mean most victims have no indication the malware is running. If QuimaRAT is on your system, it should be removed immediately.

More examples of RATs are msaRAT, Dolphin X, and Starland.

How did QuimaRAT infiltrate my computer?

LevelBlue SpiderLabs researchers Chen Aviani and Nikita Kazymirskyi documented that QuimaRAT is sold on dark web forums as a subscription service. Operators purchase access and use the Quima Builder to produce their own payloads, then distribute them through whatever methods they choose.

No specific active campaigns have been publicly identified at the time of writing, so the delivery method in any given incident depends on the individual operator. Common options include phishing emails with malicious attachments, fake software download pages, and pirated or cracked software bundles.

Malware of this kind also spreads through malvertising, unofficial download sites, and social engineering. Because the builder supports twelve output formats (including EXE, JAR, VBS, and SH), QuimaRAT payloads can be packaged to resemble almost any type of file.

How to avoid installation of malware?

Download software only from official developer websites and verified app stores. Ignore unsolicited emails with attachments or links from unknown senders. Never use pirated software, key generators, or software cracks, as these regularly serve as a vehicle for hidden malware.

Keep your operating system and all installed applications updated, and run reputable antivirus or anti-malware software. Be cautious with browser notifications from unfamiliar websites. If you believe that your computer is already infected, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.

QuimaRAT promotional listing on hacker forums (source: levelblue.com):

QuimaRAT v2.0 promotional listing

Instant automatic malware removal:

Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:

DOWNLOAD Combo Cleaner

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Quick menu:

How to remove malware manually?

Manual malware removal is a complicated task - usually it is best to allow antivirus or anti-malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for Windows.

If you wish to remove malware manually, the first step is to identify the name of the malware that you are trying to remove. Here is an example of a suspicious program running on a user's computer:

Malware process running in the Task Manager

If you checked the list of programs running on your computer, for example, using task manager, and identified a program that looks suspicious, you should continue with these steps:

manual malware removal step 1Download a program called Autoruns. This program shows auto-start applications, Registry, and file system locations:

Autoruns application appearance

manual malware removal step 2Restart your computer into Safe Mode:

Windows XP and Windows 7 users: Start your computer in Safe Mode. Click Start, click Shut Down, click Restart, click OK. During your computer start process, press the F8 key on your keyboard multiple times until you see the Windows Advanced Option menu, and then select Safe Mode with Networking from the list.

Run Windows 7 or Windows XP in Safe Mode with Networking

Video showing how to start Windows 7 in "Safe Mode with Networking":

Windows 8 users: Start Windows 8 is Safe Mode with Networking - Go to Windows 8 Start Screen, type Advanced, in the search results select Settings. Click Advanced startup options, in the opened "General PC Settings" window, select Advanced startup.

Click the "Restart now" button. Your computer will now restart into the "Advanced Startup options menu". Click the "Troubleshoot" button, and then click the "Advanced options" button. In the advanced option screen, click "Startup settings".

Click the "Restart" button. Your PC will restart into the Startup Settings screen. Press F5 to boot in Safe Mode with Networking.

Run Windows 8 in Safe Mode with Networking

Video showing how to start Windows 8 in "Safe Mode with Networking":

Windows 10 users: Click the Windows logo and select the Power icon. In the opened menu click "Restart" while holding "Shift" button on your keyboard. In the "choose an option" window click on the "Troubleshoot", next select "Advanced options".

In the advanced options menu select "Startup Settings" and click on the "Restart" button. In the following window you should click the "F5" button on your keyboard. This will restart your operating system in safe mode with networking.

Run Windows 10 in Safe Mode with Networking

Video showing how to start Windows 10 in "Safe Mode with Networking":

manual malware removal step 3Extract the downloaded archive and run the Autoruns.exe file.

Extract Autoruns.zip archive and run Autoruns.exe application

manual malware removal step 4In the Autoruns application, click "Options" at the top and uncheck "Hide Empty Locations" and "Hide Windows Entries" options. After this procedure, click the "Refresh" icon.

Refresh Autoruns application results

manual malware removal step 5Check the list provided by the Autoruns application and locate the malware file that you want to eliminate.

You should write down its full path and name. Note that some malware hides process names under legitimate Windows process names. At this stage, it is very important to avoid removing system files. After you locate the suspicious program you wish to remove, right click your mouse over its name and choose "Delete".

Delete malware in Autoruns

After removing the malware through the Autoruns application (this ensures that the malware will not run automatically on the next system startup), you should search for the malware name on your computer. Be sure to enable hidden files and folders before proceeding. If you find the filename of the malware, be sure to remove it.

Search for malware and delete it

Reboot your computer in normal mode. Following these steps should remove any malware from your computer. Note that manual threat removal requires advanced computer skills. If you do not have these skills, leave malware removal to antivirus and anti-malware programs.

These steps might not work with advanced malware infections. As always it is best to prevent infection than try to remove malware later. To keep your computer safe, install the latest operating system updates and use antivirus software. To be sure your computer is free of malware infections, we recommend scanning it with Combo Cleaner Antivirus for Windows.

Frequently Asked Questions (FAQ)

My computer is infected with QuimaRAT malware, should I format my storage device to get rid of it?

Formatting will remove QuimaRAT, but it will also erase every file on the drive. A reputable security tool such as Combo Cleaner should be tried first, as it can eliminate the malware without destroying your data.

What are the biggest issues that QuimaRAT malware can cause?

QuimaRAT can let attackers take full remote control of an infected device, steal passwords and session tokens, hijack cryptocurrency transactions via clipboard replacement, and deploy additional malware. Consequences include identity theft, financial fraud, and loss of access to accounts.

What is the purpose of QuimaRAT malware?

QuimaRAT is designed to give its operators remote control over infected computers. It also steals credentials and tokens, redirects cryptocurrency clipboard entries to the attacker's wallet, and can serve as a platform for delivering further malware to the victim's system.

How did QuimaRAT malware infiltrate my computer?

QuimaRAT is sold through dark web forums as a subscription service, so the delivery method depends on the operator who purchases it. Common vectors include phishing emails, fake software download pages, and cracked or pirated software packages containing hidden payloads.

Will Combo Cleaner protect me from malware?

Yes. Combo Cleaner can detect and remove most known malware, including threats like QuimaRAT. Because RATs can embed themselves across multiple system locations, running a full system scan is the best way to ensure no components remain on your device.

Share:

facebook
X (Twitter)
linkedin
copy link
Tomas Meskauskas

Tomas Meskauskas

Expert security researcher, professional malware analyst

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate