<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Linux Malware</title><description>Cybersecurity articles tagged #Linux Malware on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>ClingSTUN Backdoor Exploits 24 IoT Flaws for Proxy Network</title><link>https://runtimerebel.com/blog/clingstun-backdoor-exploits-24-iot-flaws-for-proxy-network</link><guid isPermaLink="true">https://runtimerebel.com/blog/clingstun-backdoor-exploits-24-iot-flaws-for-proxy-network</guid><description>The ClingSTUN Linux backdoor exploits 24 known vulnerabilities in IoT devices, turning them into proxy nodes and using STUN servers to obscure communications.</description><pubDate>Tue, 06 Oct 2026 03:52:06 GMT</pubDate><category>Iot Security</category><category>Linux Malware</category><category>Backdoor</category><category>Proxy Network</category><category>ClingSTUN</category></item><item><title>Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware</title><link>https://runtimerebel.com/blog/packagist-supply-chain-attack-8-packages-deliver-linux-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/packagist-supply-chain-attack-8-packages-deliver-linux-malware</guid><description>Security researchers identified a supply chain attack on Packagist involving eight infected packages that deploy Linux malware via GitHub Releases URLs.</description><pubDate>Sat, 23 May 2026 20:22:18 GMT</pubDate><category>Packagist</category><category>Composer</category><category>Linux Malware</category><category>Supply Chain Attack</category><category>GitHub</category></item><item><title>Showboat Linux Malware Targets Middle East Telecom via SOCKS5 Proxy</title><link>https://runtimerebel.com/blog/showboat-linux-malware-targets-middle-east-telecom-via-socks5-proxy</link><guid isPermaLink="true">https://runtimerebel.com/blog/showboat-linux-malware-targets-middle-east-telecom-via-socks5-proxy</guid><description>Researchers discover Showboat, a modular Linux post-exploitation framework used in Middle East telecom attacks to establish persistent SOCKS5 proxy backdoors.</description><pubDate>Thu, 21 May 2026 16:58:45 GMT</pubDate><category>Showboat</category><category>Linux Malware</category><category>Middle East</category><category>Telecom</category><category>SOCKS5</category><category>Black Lotus Labs</category></item><item><title>Quasar Linux RAT (QLNX) Targets Developers for Supply Chain Attacks</title><link>https://runtimerebel.com/blog/quasar-linux-rat-qlnx-targets-developers-for-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/quasar-linux-rat-qlnx-targets-developers-for-supply-chain-attacks</guid><description>A new Linux implant, Quasar Linux RAT (QLNX), targets developer systems for credential theft and network tunneling to compromise software supply chains.</description><pubDate>Fri, 08 May 2026 12:36:57 GMT</pubDate><category>QLNX</category><category>Quasar Linux RAT</category><category>Supply Chain Security</category><category>Linux Malware</category><category>Credential Theft</category></item><item><title>Stealthy Quasar Linux (QLNX) Malware Targets Developers</title><link>https://runtimerebel.com/blog/stealthy-quasar-linux-qlnx-malware-targets-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/stealthy-quasar-linux-qlnx-malware-targets-developers</guid><description>New Quasar Linux (QLNX) malware is infecting developers&apos; Linux systems, utilizing rootkit, backdoor, and credential-stealing techniques. Learn to detect and mitigate.</description><pubDate>Wed, 06 May 2026 00:46:50 GMT</pubDate><category>Quasar Linux</category><category>QLNX</category><category>Linux Malware</category><category>Rootkit</category><category>Backdoor</category><category>Software Developers</category><category>Credential Theft</category></item><item><title>Masjesu Botnet: Stealthy DDoS Malware Targets Linux IoT Devices</title><link>https://runtimerebel.com/blog/masjesu-botnet-stealthy-ddos-malware-targets-linux-iot-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/masjesu-botnet-stealthy-ddos-malware-targets-linux-iot-devices</guid><description>Masjesu is a highly evasive DDoS botnet targeting Linux IoT devices. It prioritizes persistence and avoids critical infrastructure to remain undetected.</description><pubDate>Wed, 08 Apr 2026 12:27:42 GMT</pubDate><category>Masjesu</category><category>Iot Security</category><category>DDoS Botnet</category><category>Linux Malware</category><category>Persistence Mechanisms</category></item><item><title>US Authorities Disrupt SocksEscort Proxy and AVRecon Botnet</title><link>https://runtimerebel.com/blog/us-authorities-disrupt-socksescort-proxy-and-avrecon-botnet</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-authorities-disrupt-socksescort-proxy-and-avrecon-botnet</guid><description>US and international law enforcement dismantle the SocksEscort proxy network and AVRecon botnet, which hijacked over 100,000 Linux-based edge devices.</description><pubDate>Thu, 12 Mar 2026 16:28:53 GMT</pubDate><category>AVRecon</category><category>SocksEscort</category><category>Botnet Disruption</category><category>Linux Malware</category><category>Edge Security</category></item><item><title>GRIDTIDE Espionage: PRC-Nexus UNC2814 Targets Telecoms Globally</title><link>https://runtimerebel.com/blog/gridtide-espionage-prc-nexus-unc2814-targets-telecoms-globally</link><guid isPermaLink="true">https://runtimerebel.com/blog/gridtide-espionage-prc-nexus-unc2814-targets-telecoms-globally</guid><description>Google disrupts GRIDTIDE, a novel backdoor used by PRC-nexus UNC2814 for global cyber espionage against telecommunications and government entities.</description><pubDate>Wed, 25 Feb 2026 16:34:59 GMT</pubDate><category>UNC2814</category><category>GRIDTIDE</category><category>PRC Nexus</category><category>Cyber Espionage</category><category>Telecommunications</category><category>Government</category><category>Google Sheets API</category><category>SoftEther VPN</category><category>C2</category><category>Linux Malware</category><category>TTPs</category></item></channel></rss>