Quasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and Persistence

2026-05-10T08:51:47Z5e6ece681d009510e43f9f26621fabdb9bc38d51b7385872d0e61d1c73c758ee
CISAICSPAN-OSRATcredential theftdata breachfilelesskernel exploitknown-exploited-vulnerabilitylinuxmalwareprivilege escalationransomwaresupply chainzero-day

What happened

Multiple high-impact incidents and vulnerabilities reported: a new fileless Linux RAT (Quasar Linux RAT, QLNX) targeting developers for credential theft and persistence; an active PAN-OS zero‑day (CVE-2026-0300) exploited by suspected nation‑state actors to gain root and tunnel traffic; a public Linux kernel local privilege‑escalation (Dirty Frag) with working exploit; supply‑chain and credential exposures (Braintrust AWS breach, Zara third‑party compromise tied to ShinyHunters); RansomHouse claiming a breach of Trellix; confirmed ICS intrusions against Polish water plants attributed to likely

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
5e6ece681d009510e43f9f26621fabdb9bc38d51b7385872d0e61d1c73c758ee
Enrichment time
2026-05-10T08:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.