logo

Linux malware “perfctl” behind years-long cryptomining campaign

ID: beff9910-4726-5411-9d27-9ec26b819ba2

STIX ID: report--beff9910-4726-5411-9d27-9ec26b819ba2

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-10-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Aqua Nautilus researchers describe 'perfctl', a long-running, highly evasive Linux cryptomining malware that exploits misconfigurations and known vulnerabilities (notably CVE-2023-33246 and CVE-2021-4034) to deploy rootkits, replace system utilities, and mine Monero over TOR; the report covers infection vectors, persistence locations, evasion mechanisms, IoCs, detection methods, and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.