QLNX Targets Developers With Credential Theft Designed for Supply Chain Compromise
ID: d0a4e6b9-6d90-5fb8-8cbe-5be600ec4163
STIX ID: report--d0a4e6b9-6d90-5fb8-8cbe-5be600ec4163
Feed Name: cybersecurityNews.com
Quasar Linux (QLNX) is a sophisticated Linux remote-access trojan that operates in memory, compiles and injects a rootkit and PAM backdoor at runtime, harvests a wide range of developer credentials (SSH keys, cloud configs, NPM/PyPI tokens, etc.), uses eBPF-level hiding and P2P relaying to resist detection and removal, and includes extensive persistence and log-wiping capabilities; the report includes multiple file and hash IoCs and recommended detection steps for developer and cloud environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
