logo

perfctl: A Stealthy Malware Targeting Millions of Linux Servers

ID: 17c184b4-e5f7-54ca-9601-85b00926b9e2

STIX ID: report--17c184b4-e5f7-54ca-9601-85b00926b9e2

Feed Name: Aqua Security Blog

Threat Score
72/100

Date Published: 2024-10-03

Date Updated: 2026-04-26

...
...

Perfctl is a long-running Linux malware campaign that leverages exposed services and misconfigurations (including RocketMQ CVE-2023-33246 and attempts to exploit Polkit CVE-2021-4034) to deliver a packed ELF dropper that installs a rootkit, trojanized userland utilities, a Monero cryptominer, and proxy-jacking components; it uses process masquerading, LD_PRELOAD hooks, Unix sockets for local coordination, and TOR for external C2, and the report includes IOCs, detailed TTPs, detection guidance, and mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.