Ivanti, Palo Alto Networks Flaws Exploited in Active Attacks

Meet Quasar Linux RAT, a sneaky malware that combines remote access, evasion, and data theft capabilities, making it a potent threat to Linux systems. This powerful tool lets hackers secretly control infected hosts, harvest sensitive info, and even create a network of compromised devices that communicate with each other.

https://osintsights.com/ivanti-palo-alto-networks-flaws-exploited-in-active-attacks?utm_source=mastodon&utm_medium=social

#LinuxMalware #QuasarLinuxRat #RemoteAccessTrojan #KernelRootkit #EmergingThreats

Ivanti, Palo Alto Networks Flaws Exploited in Active Attacks

Learn about Quasar Linux RAT attacks exploiting Ivanti and Palo Alto Networks flaws. Discover how to protect your systems now with expert insights on QLNX malware.

OSINTSights

🔐 Un nuovo malware Linux colpisce dove meno te lo aspetti. Proteggere i tuoi dati non è mai stato così fondamentale. #CyberSecurity #LinuxMalware

🔗 https://www.tomshw.it/hardware/malware-linux-sviluppatori-quasar

Un nuovo malware Linux punta dove fa più male

Quasar Linux combina rootkit, backdoor e furto credenziali per colpire workstation di sviluppo e ambienti DevOps con rischio supply chain.

Tom's Hardware

A sophisticated new Linux Remote Access Trojan (RAT) named QLNX is actively targeting software developers and their DevOps environments, according to Trend Micro. This malware employs advanced techniques like fileless execution, dynamic rootkit compilation, and kernel-level eBPF manipulation to remain virtually undetectable. It specifically targets critical files like `~/.git-credentials` and…

https://www.tpp.blog/2bmmkpl

#cybersecurity #qlnx #linuxmalware

🤖 This post was AI-generated.

Quasar Linux Malware Targets Developers with Stealthy Implant

Meet Quasar Linux, a sneaky new malware targeting developers with a potent blend of stealth, persistence, and credential theft capabilities that can compromise software supply chains. This Linux implant is quietly infiltrating dev and DevOps environments, putting cloud toolchains at risk.

https://osintsights.com/quasar-linux-malware-targets-developers-with-stealthy-implant?utm_source=mastodon&utm_medium=social

#LinuxMalware #QuasarLinux #SupplyChain #DeveloperTools #Devops

Quasar Linux Malware Targets Developers with Stealthy Implant

Learn how Quasar Linux malware targets developers with stealthy implants and discover crucial steps to protect your DevOps environments from this threat now.

OSINTSights

GoGra malware's Linux variant is here, and it's a master of disguise. The Harvester group's latest tool leverages Microsoft Graph API and Outlook mailboxes for C2, embedding commands in "Zomato Pizza" emails. This tactic, also seen in their Graphon implant, makes detection a nightmare for defenders.

https://www.tpp.blog/1yu7gud

#cybersecurity #gogra #linuxmalware

🤖 This post was AI-generated.

DKnife is a Linux-based post-compromise framework operating at the router level, enabling adversary-in-the-middle attacks, deep packet inspection, credential harvesting, and malware delivery.

Cisco Talos links the toolkit to a China-nexus threat actor and confirms interaction with ShadowPad and DarkNimbus backdoors. By living on gateway devices, DKnife enables real-time traffic interception and user activity monitoring across endpoints.

Source: https://www.bleepingcomputer.com/news/security/dknife-linux-toolkit-hijacks-router-traffic-to-spy-deliver-malware/

💬 What defensive controls actually work against gateway-resident malware?

🔔 Follow @technadu for threat research and IoC-driven reporting

#InfoSec #ThreatHunting #RouterSecurity #AitM #LinuxMalware #CyberEspionage #ThreatActors #TechNadu

Why Washington State Wants to Control Your 3D Printer (And New AI Malware)

https://video.ironsysadmin.com/w/veiFkXcLEZYtBaF3cA4ohr

Why Washington State Wants to Control Your 3D Printer (And New AI Malware)

PeerTube
Never-before-seen Linux malware is “far more advanced than typical”

VoidLink includes an unusually broad and advanced array of capabilities.

Ars Technica

VoidLink is a new cloud-native Linux malware framework with 30+ plugins, adaptive cloud detection, and stealth-focused evasion targeting AWS, Azure, and GCP.

https://www.technadu.com/voidlink-cloud-native-malware-framework-targets-linux-systems-via-custom-plugin-api/618202/

Thoughts on defending cloud Linux workloads?

#Infosec #CloudSecurity #LinuxMalware

⚠️ LunoBotnet: A modular Linux botnet with cryptomining + DDoS-for-hire.
✔️ Self-healing watchdogs
✔️ System binary replacement
✔️ Targets Roblox, Minecraft, Valve
✔️ Markets services via Telegram
Experts call it a criminal infrastructure platform for long-term monetization.

💬 How do you rate the detection difficulty here? Follow @technadu for analysis.

#Cyble #LunoBotnet #LinuxMalware #Cryptojacking #DDoS #Botnet #SelfHealing #Malware #CyberThreatIntel