Briefing

QLNX: Undocumented Linux RAT Targets Developers and DevOps Credentials

security
by [email protected] (The Hacker News) ·

Deploy updated antivirus signatures and monitor for QLNX activity; isolate affected systems immediately.

What to do now

Deploy updated antivirus signatures and monitor for QLNX activity; isolate affected systems immediately.

Summary

QLNX, a previously undocumented Linux‑based Remote Access Trojan, has been identified as a silent foothold for threat actors targeting developers' systems.

The implant is designed to harvest credentials, keylog user input, manipulate files, monitor the clipboard, and tunnel network traffic to exfiltrate data. QLNX specifically focuses on DevOps credentials across the software supply chain, allowing attackers to compromise build pipelines and deployment environments. The malware remains undetected by many traditional security tools due to its stealthy persistence mechanisms. Researchers have observed QLNX establishing a foothold by exploiting vulnerable services and then pivoting to other systems within the network. The RAT can also perform file manipulation and clipboard monitoring to capture sensitive information. It is capable of tunneling network traffic to bypass perimeter defenses. The discovery of QLNX underscores the need for continuous monitoring of Linux hosts in development environments.

Key changes

  • QLNX is a Linux‑based Remote Access Trojan targeting developers.
  • It harvests credentials, keylogs, file manipulation, clipboard monitoring, and network tunneling.
  • The RAT focuses on DevOps credentials across the software supply chain.
  • It establishes a silent foothold and uses stealthy persistence.
  • It can pivot to other systems within the network.
  • It remains undetected by many traditional security tools.

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting