perfctl: A Stealthy Malware Targeting Millions of Linux Servers
ID: 17c184b4-e5f7-54ca-9601-85b00926b9e2
STIX ID: report--17c184b4-e5f7-54ca-9601-85b00926b9e2
Feed Name: Aqua Security Blog
Perfctl is a long-running Linux malware campaign that leverages exposed services and misconfigurations (including RocketMQ CVE-2023-33246 and attempts to exploit Polkit CVE-2021-4034) to deliver a packed ELF dropper that installs a rootkit, trojanized userland utilities, a Monero cryptominer, and proxy-jacking components; it uses process masquerading, LD_PRELOAD hooks, Unix sockets for local coordination, and TOR for external C2, and the report includes IOCs, detailed TTPs, detection guidance, and mitigation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
