Tag: Quasar Linux malware

New stealthy Quasar Linux malware targets software developers
News

New stealthy Quasar Linux malware targets software developers

Developers' computers are being targeted by Quasar Linux (QLNX), an undocumented Linux implant that combines rootkit, backdoor, and credential-stealing capabilities. The malware kit is used in AWS, Docker, Kubernetes, GitHub, PyPI, npm, and DevOps settings. Supply-chain attacks, in which the threat actor posts malicious packages on code distribution platforms, may be made possible by this. After analyzing the QLNX implant, researchers at cybersecurity firm Trend Micro discovered that it uses gcc [GNU Compiler Collection] to dynamically create PAM backdoor modules and rootkit shared objects on the target host. According to a report released by the business this week, QLNX was created for long-term persistence and stealth since it operates in-memory, wipes logs, spoofs process name...