Quasar Linux RAT Developer Credential Theft | MSSP Advisory
High
DateMay 8, 2026
📋Executive Summary
A new Linux RAT called Quasar Linux RAT (QLNX) specifically targets developer systems to steal credentials and establish persistent access for supply chain attacks. The malware performs credential harvesting, keylogging, file manipulation, and network tunneling to compromise software development environments. QLNX aims to infiltrate the software supply chain by compromising developer and DevOps credentials.
⚠️Why It Matters for MSSPs
Your RMM agents and remote access tools likely run on Linux endpoints in client developer environments, making them potential entry points for this RAT. When QLNX compromises a client's development pipeline, any software they build becomes a vector to spread malware to their customers, creating liability exposure for your advisory practice.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Supply Chain
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.