Quasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and Persistence
ID: e4e1c978-369c-5ce8-8da5-0bab90f2ce5f
STIX ID: report--e4e1c978-369c-5ce8-8da5-0bab90f2ce5f
Feed Name: Security Affairs
**Quasar Linux RAT (QLNX)** is a sophisticated, fileless Linux remote access trojan designed for stealthy long-term intrusion in developer and DevOps environments. The implant runs from memory (using memfd), dynamically compiles and deploys an LD_PRELOAD rootkit and PAM backdoor, abuses systemd/cron/init/XDG and LD_PRELOAD for persistence, hides via userland rootkit and optional eBPF kernel-level hiding, and harvests credentials (SSH keys, browser profiles, plaintext via PAM), clipboard and system data; it also supports remote shell, keylogging, screenshots, SOCKS/proxying, and a P2P mesh for resilient C2. QLNX communicates over custom TLS/HTTPS/HTTP channels, uses a distinct protocol magic value "QLNX", and poses a supply-chain and developer-environment risk due to its credential-stealing and persistence capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
