Quasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and Persistence

2026-05-09T20:51:56Z8daeff028c569a99109a59700b023c0f38aa5ffc4dabaf77af66e547e8e3ae21
ABWAI-supply-chainAPTBraintrustDirty-FragICSQLNXRansomHouseShinyHuntersTrellixZaraapi-keyscloud-secretscredential-theftdata-breachfileless-malwarekeyloggerlinuxlinux-kernelpersistenceprivilege-escalation','zero-day'quasar-linux-ratransomwarerussia-linkedwater-treatment

What happened

This feed reports multiple high‑impact security incidents and disclosures: researchers uncovered Quasar Linux RAT (QLNX), a previously undocumented fileless Linux implant targeting developers for credential theft, keylogging, clipboard monitoring, file manipulation, tunneling and persistence; Braintrust suffered an AWS account compromise potentially exposing API keys for cloud AI models and urged customers to rotate secrets; RansomHouse claims a breach of cybersecurity vendor Trellix with screenshots of internal systems; Poland’s ABW detailed Russia‑linked APT intrusions against five water‑t​r

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8daeff028c569a99109a59700b023c0f38aa5ffc4dabaf77af66e547e8e3ae21
Enrichment time
2026-05-09T20:51:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.