Quasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and Persistence
2026-05-09T20:51:56Z•8daeff028c569a99109a59700b023c0f38aa5ffc4dabaf77af66e547e8e3ae21
ABWAI-supply-chainAPTBraintrustDirty-FragICSQLNXRansomHouseShinyHuntersTrellixZaraapi-keyscloud-secretscredential-theftdata-breachfileless-malwarekeyloggerlinuxlinux-kernelpersistenceprivilege-escalation','zero-day'quasar-linux-ratransomwarerussia-linkedwater-treatment
What happened
This feed reports multiple high‑impact security incidents and disclosures: researchers uncovered Quasar Linux RAT (QLNX), a previously undocumented fileless Linux implant targeting developers for credential theft, keylogging, clipboard monitoring, file manipulation, tunneling and persistence; Braintrust suffered an AWS account compromise potentially exposing API keys for cloud AI models and urged customers to rotate secrets; RansomHouse claims a breach of cybersecurity vendor Trellix with screenshots of internal systems; Poland’s ABW detailed Russia‑linked APT intrusions against five water‑tr
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 8daeff028c569a99109a59700b023c0f38aa5ffc4dabaf77af66e547e8e3ae21
- Enrichment time
- 2026-05-09T20:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.