logo

New Linux Malware ‘Perfctl’ Targets Millions by Mimicking System Files

ID: a490e93b-1cf4-5ae9-aaa6-972de17cc39e

STIX ID: report--a490e93b-1cf4-5ae9-aaa6-972de17cc39e

Feed Name: HackRead

Threat Score
70/100

Date Published: 2024-10-03

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Aqua Nautilus researchers report on "Perfctl", a stealthy Linux malware campaign that mimics system files and employs rootkits, deceptive filenames, Unix sockets and Tor to evade detection and maintain persistence; it targets misconfigurations (and attempts to abuse CVE-2021-4043) to gain privileges and is primarily used for cryptomining, proxy-jacking and hijacking server resources, potentially affecting thousands to millions of Linux servers. Recommended mitigations include patching, vulnerability assessments, monitoring and endpoint protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.