ThreatCluster

Quasar Linux RAT Targets Developers with Advanced Fileless Attacks

First seen 27 May 2026, 01:09 UTC GbhackersCybersecuritynews 92% similarity 67

Article Content

Browse articles
ThreatCluster

Quasar Linux (QLNX) is a newly identified Remote Access Trojan specifically targeting software developers and DevOps engineers. It employs sophisticated techniques such as fileless execution, an eBPF rootkit, and PAM backdoors to infiltrate systems, making detection challenging for traditional security measures. The malware operates primarily in memory, avoiding file storage, which is a common detection vector. Its peer-to-peer command and control (C2) mesh further complicates mitigation efforts. The attacks are indicative of a growing trend in targeting the software supply chain, posing significant risks to organizations reliant on Linux systems. Current reports indicate that the malware is actively being exploited, emphasizing the need for heightened security awareness among affected professionals.

Key Points: • Quasar Linux (QLNX) targets developers and DevOps with advanced fileless techniques. • The malware uses an eBPF rootkit and PAM backdoors to evade detection. • Active exploitation of QLNX highlights significant risks to the software supply chain.

ThreatCluster AI

Timeline

2026-05-26
Quasar Linux RAT discovered
Security researchers identified Quasar Linux, a sophisticated RAT targeting developers with fileless execution methods.
Gbhackers
2026-05-26
Malware details released
Reports detailed the use of an eBPF rootkit and peer-to-peer C2 mesh in Quasar Linux attacks.
Cybersecuritynews

Community

Browse all →