Skip to content
ThreatCluster

Quasar Linux RAT Targets Developers with Advanced Fileless Attacks

First seen 27 May 2026, 01:09 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 28, 2026 at 01:08 UTC
  • Quasar Linux (QLNX) targets developers and DevOps with advanced fileless techniques.
  • The malware uses an eBPF rootkit and PAM backdoors to evade detection.
  • Active exploitation of QLNX highlights significant risks to the software supply chain.

Quasar Linux (QLNX) is a newly identified Remote Access Trojan specifically targeting software developers and DevOps engineers. It employs sophisticated techniques such as fileless execution, an eBPF rootkit, and PAM backdoors to infiltrate systems, making detection challenging for traditional security measures. The malware operates primarily in memory, avoiding file storage, which is a common detection vector. Its peer-to-peer command and control (C2) mesh further complicates mitigation efforts. The attacks are indicative of a growing trend in targeting the software supply chain, posing significant risks to organizations reliant on Linux systems. Current reports indicate that the malware is actively being exploited, emphasizing the need for heightened security awareness among affected professionals.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 108d ago How this analysis works

Timeline

2026-05-26
Quasar Linux RAT discovered
Security researchers identified Quasar Linux, a sophisticated RAT targeting developers with fileless execution methods.
Gbhackers
2026-05-26
Malware details released
Reports detailed the use of an eBPF rootkit and peer-to-peer C2 mesh in Quasar Linux attacks.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track QLNX in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed