CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Quasar Linux (QLNX) - A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6215

As cited

Copy frozen at (site build).

threat intel

Quasar Linux (QLNX) - A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities

TrendAI Research identified Quasar Linux (QLNX), a previously undocumented remote access trojan (RAT) for Linux systems that combines rootkit functionality, pluggable authentication module (PAM) backdoor capabilities, and credential harvesting. The malware maintains low detection rates and enables stealthy persistence and lateral movement within compromised environments.

Why it matters: Linux infrastructure operators and supply chain partners need to assess exposure to this undetected RAT, particularly given its rootkit and credential theft capabilities that could enable long-term unauthorized access and pivot to other systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary