logo

New stealthy Quasar Linux malware targets software developers

ID: 73e1e8dc-ed49-509d-9b61-d8cc424117b0

STIX ID: report--73e1e8dc-ed49-509d-9b61-d8cc424117b0

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Bill Toulas

...
...

Trend Micro analyzed a previously undocumented Linux implant called Quasar Linux (QLNX) that targets developers and DevOps environments (npm, PyPI, GitHub, AWS, Docker, Kubernetes). QLNX features a 58-command RAT, dynamic compilation of userland rootkit components, a kernel-level eBPF stealth layer, credential harvesting (including PAM backdoors and SSH/browser/cloud credentials), extensive persistence (LD_PRELOAD, systemd, crontab, init.d, XDG autostart, .bashrc), in-memory execution, process injection, and filesystem monitoring; Trend Micro provided IoCs and notes low detection coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.