Quasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and Persistence
2026-05-10T08:51:47Z•5e6ece681d009510e43f9f26621fabdb9bc38d51b7385872d0e61d1c73c758ee
CISAICSPAN-OSRATcredential theftdata breachfilelesskernel exploitknown-exploited-vulnerabilitylinuxmalwareprivilege escalationransomwaresupply chainzero-day
What happened
Multiple high-impact incidents and vulnerabilities reported: a new fileless Linux RAT (Quasar Linux RAT, QLNX) targeting developers for credential theft and persistence; an active PAN-OS zero‑day (CVE-2026-0300) exploited by suspected nation‑state actors to gain root and tunnel traffic; a public Linux kernel local privilege‑escalation (Dirty Frag) with working exploit; supply‑chain and credential exposures (Braintrust AWS breach, Zara third‑party compromise tied to ShinyHunters); RansomHouse claiming a breach of Trellix; confirmed ICS intrusions against Polish water plants attributed to likely
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 5e6ece681d009510e43f9f26621fabdb9bc38d51b7385872d0e61d1c73c758ee
- Enrichment time
- 2026-05-10T08:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.