perfctl campaign targeting Docker API (Campaign)
ID: e80ab416-06af-5a73-9dcf-4db1abd8715e
STIX ID: report--e80ab416-06af-5a73-9dcf-4db1abd8715e
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-10-21
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Attackers are scanning for exposed Docker Remote API servers and creating privileged containers to deploy a new cryptomining malware named "perfctl." Once executed inside containers, perfctl disables security tooling, modifies system configurations to persist, and uses host resources for cryptocurrency mining, degrading performance and posing a security risk to systems with exposed Docker APIs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
