Quasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and Persistence
2026-05-09T14:51:43Z•6236e40cae0ef318c29b03f340d926c8a9469d9c8b3c01ce999f3bc3f2d333f5
CISA-KEVCiscoICSIvantiPAN-OSRATcloud-credentialscredential-theftdata-breachexploited-in-the-wildfilelesskernel-vulnerabilitykeystroke-logginglinuxmalwarenation-stateprivilege-escalationransomwaresupply-chainzero-day
What happened
Feed highlights multiple high-impact security incidents and active exploits: a new fileless Linux RAT (Quasar Linux RAT - QLNX) targeting developers for credential theft and persistence; an unpatched Linux kernel local root vulnerability dubbed “Dirty Frag” with public exploit; active exploitation of a Palo Alto PAN-OS zero‑day (CVE-2026-0300) by suspected nation‑state actors to gain root and deploy tunneling tools; and a variety of supply‑chain and account‑compromise incidents (Braintrust AWS account breach exposing API keys, RansomHouse claiming access to Trellix internal systems, and a Shny
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 6236e40cae0ef318c29b03f340d926c8a9469d9c8b3c01ce999f3bc3f2d333f5
- Enrichment time
- 2026-05-09T14:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.