logo

perfctl Malware Targeting Linux (Campaign)

ID: 4b2a17ea-ce65-5aba-865d-7c5272f7dd6a

STIX ID: report--4b2a17ea-ce65-5aba-865d-7c5272f7dd6a

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2024-10-03

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

perfctl is a stealthy Linux malware campaign that exploits misconfigurations and CVE-2021-4043 (Polkit) to escalate privileges, installs rootkits that hook libpcap and PAM to evade logging and monitoring, and uses process masquerading and trojanized system utilities (e.g., ldd, lsof, top) to hide. It deploys cryptominers (XMRIG), performs proxy-jacking, establishes TOR-based backdoors and Unix-socket internal communication, and hides activity by deleting initial binaries and suppressing noisy behavior when users are present, making detection and remediation difficult.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.