← Back to Feed
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities
May 4, 2026 · Trend Micro · Severity: HIGH
TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, and potential supply-chain attacks.
Key Takeaways
- TrendAI Research analyzed Quasar Linux, or QLNX, a previously undocumented sophisticated Linux RAT.
- The malware incorporates a rootkit, PAM backdoor, and credential harvesting capabilities.
- QLNX has low detection rates, enabling stealthy access in supply chain environments.