New Perfctl Malware Attacking Millions of Linux Servers
ID: f85fcf92-cada-5811-a54a-937af8fd0392
STIX ID: report--f85fcf92-cada-5811-a54a-937af8fd0392
Feed Name: cybersecurityNews.com
**Perfctl** is a stealthy, persistent Linux-targeting malware campaign that uses rootkits, fileless execution, and TOR-based communications to run Monero cryptominers and proxy-jacking tools across potentially millions of misconfigured servers; the report details its evasion and persistence techniques, exploitation of a Polkit vulnerability, common indicators (suspicious binaries in /tmp, /usr, /root, unusual CPU spikes, TOR traffic), and recommended mitigations such as patching, restricting execution in writable directories, and deploying runtime protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
