Quasar Linux RAT Targets Developers with Advanced Fileless Attacks
Article Content
- •Quasar Linux (QLNX) targets developers and DevOps with advanced fileless techniques.
- •The malware uses an eBPF rootkit and PAM backdoors to evade detection.
- •Active exploitation of QLNX highlights significant risks to the software supply chain.
Quasar Linux (QLNX) is a newly identified Remote Access Trojan specifically targeting software developers and DevOps engineers. It employs sophisticated techniques such as fileless execution, an eBPF rootkit, and PAM backdoors to infiltrate systems, making detection challenging for traditional security measures. The malware operates primarily in memory, avoiding file storage, which is a common detection vector. Its peer-to-peer command and control (C2) mesh further complicates mitigation efforts. The attacks are indicative of a growing trend in targeting the software supply chain, posing significant risks to organizations reliant on Linux systems. Current reports indicate that the malware is actively being exploited, emphasizing the need for heightened security awareness among affected professionals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track QLNX in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…