← Back to Feed
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities
May 4, 2026 · Trend Micro · Severity: HIGH
TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, and potential supply-chain attacks.
Key Takeaways
- TrendAI Research detailed Quasar Linux, a previously undocumented Linux RAT with low detection rates that includes a rootkit, PAM backdoor, and credential harvesting capabilities.
- The QLNX malware provides stealthy persistent access and is described as a silent foothold in the software supply chain.
- Linux defenders should hunt for rootkit and PAM backdoor indicators and treat suspicious packages as potential supply chain compromises.