logo

Near-'perfctl' Fileless Malware Targets Millions of Linux Servers

ID: 1158bfe5-c498-5f36-adce-4fba24501792

STIX ID: report--1158bfe5-c498-5f36-adce-4fba24501792

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-10-03

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Aqua Nautilus analysis reveals 'perfctl' (aka perfcc), a persistent, multipurpose Linux dropper actively compromising Internet-facing servers worldwide to deploy cryptominers, proxyjacking tools, credential-stealing utilities and backdoors. The actor leverages a vast catalogue of misconfiguration checks and known CVEs (including Apache RocketMQ RCE) to gain access, employs user- and kernel-level rootkits, process masquerading, Tor-based command channels and fileless persistence to evade detection, and likely compromised thousands of systems with millions at risk; recommended mitigations include patching, restricting execution on writable dirs, disabling unused services, strict privilege management, network segmentation and runtime protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.