Attackers have found a new way to turn Linux systems into hidden supply chain distribution nodes that are resistant to takedowns. Researchers at Trend Micro have uncovered a new malware framework, dubbed Quasar Linux or QLNX, which is described as a modular remote access Trojan (RAT) for Linux. What sets the campaign apart is the malware’s use of a P2P meshing feature that turns individual implants into an interconnected network of infections, making the campaign difficult to neutralize.
See also: Canonical: AI features in Ubuntu Linux distro

QLNX also combines kernel-level rootkit functionality, PAM-based authentication backdoors, and persistence mechanisms to remain hidden on compromised systems while allowing attackers access. “The Quasar Linux RAT (QLNX) is a comprehensive Linux implant that combines remote access capabilities with advanced obfuscation, persistence, keylogging, and credential harvesting capabilities,” the researchers said in a blog post.
“The malware contains embedded C code for both the PAM backdoor and the LD_PRELOAD rootkit as alphanumerics within the binary.“
Threat monitoring includes setting up detection for Indicators of Compromise (IOCs) shared by Trend Micro, which are now applied to protections subscribed to by Trend Vision One customers.
P2P networking and multi-layered C2 infrastructure
The disclosure highlights a robust command and control (C2) design that is intended to withstand takedowns and disruptions. The researchers said QLNX supports peer-to-peer (P2P) mesh networking, allowing compromised systems to communicate with each other rather than relying solely on central servers.
This turns infected Linux systems into interconnected relay points capable of maintaining communication even when parts of the infrastructure are disrupted. This is another factor that contributes to the difficulty of complete eradication.
The command and control (C2) system operates with a flexible command suite. “In total, QLNX records 58 separate commands, covering a wide range of post-compromise operations, including file system management, network tunneling, credential harvesting, and rootkit management,” the researchers said, describing a full list of recorded commands and their corresponding handlers.
For network communication, QLNX supports raw TCP, HTTPS, and HTTP. “All three transports carry the same underlying binary command protocol,” Trend Micro wrote. “Both TCP and HTTPS channels are secured using TLS, ensuring that commands and data exchanges are encrypted during network communication.”
See also: CISA adds Linux vulnerability to KEV List

Researchers also wrote about QLNX's use of rootkits and Linux Pluggable Authentication Modules (PAM) to establish long-term persistence. According to Trend Micro, the malware leverages rootkit functionality to hide malicious activities, processes, and assets from management tools and security monitoring systems.
The malware was also observed interfering with PAM, a core Linux authentication framework responsible for handling login verification across many services. By modifying PAM elements, attackers could potentially capture credentials, maintain access, or bypass authentication checks even after passwords are changed.
Trend Micro warned that these techniques significantly increase the difficulty of elimination, as they ensure persistence even after the visible malware artifacts are eliminated.
Trend Micro's analysis describes QLNX as a modular Linux malware framework designed for stealth. It relies on a multi-layered internal logic that allows operators to dynamically load capabilities, maintain persistence, and execute commands without raising an alarm.
One particular feature highlighted by the researchers was the malware's process impersonation behavior. It hides malicious processes under names that mimic legitimate Linux services and binaries to integrate into routine administrative workflows.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The malware also embraces the ongoing trend of fileless delivery. “Upon execution, QLNX copies itself to a memory file, re-executes from that memory copy, and deletes the original binary from disk, leaving no disk footprint,” the disclosure added.
See also: Copy Fail: Linux vulnerability allows root access to systems

Trend Micro added a list of IOCs, including file hashes, hardcoded passwords, credential harvesting targets, and other syntax and persistence artifacts, to support detection efforts.
