s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.qlnx

📛 Threat Title

Malware family: QLNX

Category: QLNX First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.qlnx`. Printable name: QLNX. Aliases: Quasar Linux RAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.qlnx VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.qlnx

IOC database

Type
domain
Value
elf.qlnx
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.qlnx

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.qlnx

References (1)

Remediations (10)

  • web:cipherssecurity.com

    A previously undocumented Linux malware family named Quasar Linux ( QLNX ) is targeting software developers with a combination of a userland rootkit, a kernel-level stealth component, a PAM backdoor, and a 58-command remote access framework — while only four security solutions currently detect it. Trend Micro researchers published their analysis on May 4, 2026, disclosing a full-featured ...

  • web:cyberpress.org

    Cybersecurity researchers have uncovered a highly sophisticated Linux remote access trojan known as Quasar Linux, or QLNX . This previously undocumented malware specifically targets developers and DevOps engineers to steal credentials, paving the way for massive supply chain attacks.

  • web:dailysecurityreview.com

    Security Affairs published analysis on May 9, 2026 of QLNX — a fileless Linux implant that combines an eBPF kernel rootkit with a PAM authentication backdoor — finding the malware evaded detection by all but four antivirus engines on VirusTotal, while systematically harvesting developer supply chain credentials from infected Linux CI/CD hosts. How QLNX's eBPF Rootkit and LD_PRELOAD Hooks ...

  • web:labs.cloudsecurityalliance.org

    Key Takeaways Trend Micro researchers disclosed Quasar Linux ( QLNX ) in May 2026 as a previously undocumented, full-featured Linux remote access trojan designed specifically to compromise developer and DevOps workstations and harvest software supply chain credentials [1]. QLNX employs a two-tier rootkit—a userland LD_PRELOAD hook combined with a kernel-level eBPF component—plus a Pluggable ...

  • web:securityaffairs.com

    This design increases resilience because the malware can maintain communication and coordination even if parts of its command infrastructure are disrupted, making full removal from an environment significantly more difficult. "The QLNX implant was built for long-term stealth and credential theft.

  • web:socprime.com

    Summary Quasar Linux ( QLNX ) is an advanced Linux remote access trojan that combines a user-space and eBPF rootkit with a PAM backdoor and broad credential-harvesting capabilities. The malware supports fileless execution, process name masquerading, and several persistence techniques that help it remain hidden on infected systems.

  • web:thehackernews.com

    Quasar Linux RAT ( QLNX ) harvests DevOps credentials to enable software supply chain attacks with fileless execution and dual rootkit stealth.

  • web:www.cybersecurity-review.com

    What followed was the discovery of Quasar Linux ( QLNX ), a previously undocumented Linux remote access trojan (RAT) with rootkit capabilities and a notably minimal detection footprint.

  • web:www.linkedin.com

    QLNX is a previously undocumented multi-functional malware kit integrating rootkit, backdoor, and credential-stealing capabilities.

  • web:www.trendmicro.com

    TrendAI™ Research breaks down Quasar Linux ( QLNX ), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, and potential supply-chain attacks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.