logo

Threat Actors Abuse Fileless Execution to Spread Quasar Linux RAT

ID: 3574e18a-237a-508e-b9d2-0ad6242aa479

STIX ID: report--3574e18a-237a-508e-b9d2-0ad6242aa479

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Varshini

...
...

Quasar Linux (QLNX) is a sophisticated fileless Linux RAT that infects developer/DevOps workstations on mainstream distributions, using memfd_create to execute in-memory, dynamically compiling an eBPF kernel rootkit and a PAM backdoor via the host GCC to capture cleartext credentials and exfiltrate SSH keys, cloud/Kubernetes secrets, and registry tokens; it persists via /etc/ld.so.preload modifications, drops dynamically compiled shared objects (/usr/lib/libsecurity_utils.so.1, /usr/lib/.libpam_cache.so), and uses a resilient P2P mesh for C2, evading traditional EDR and static detection—report includes IOCs and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.