Linux malware “perfctl” behind years-long cryptomining campaign
ID: beff9910-4726-5411-9d27-9ec26b819ba2
STIX ID: report--beff9910-4726-5411-9d27-9ec26b819ba2
Feed Name: Bleeping Computer
Threat Score
Aqua Nautilus researchers describe 'perfctl', a long-running, highly evasive Linux cryptomining malware that exploits misconfigurations and known vulnerabilities (notably CVE-2023-33246 and CVE-2021-4034) to deploy rootkits, replace system utilities, and mine Monero over TOR; the report covers infection vectors, persistence locations, evasion mechanisms, IoCs, detection methods, and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
