New Perfctl Malware Targets Linux Servers for Cryptocurrency Mining and Proxyjacking

A newly discovered malware, Perfctl, is actively exploiting vulnerable Linux servers to install cryptocurrency miners and proxyjacking software. This stealthy malware hides itself by mimicking legitimate processes, evading detection, and persisting even after system reboots.
- Perfctl is stealthy and persistent, halting activity when users log in and running only during idle times to avoid detection.
- The malware leverages a security flaw in Polkit (CVE-2021-4043) to escalate privileges and deploy a cryptocurrency miner known as perfcc.
- Perfctl disguises itself by adopting the names of legitimate Linux system processes, making detection challenging.
- Attackers exploit misconfigured Linux servers, using the vulnerable Apache RocketMQ instance to deliver the malware payload.
- The malware also installs a rootkit for defense evasion and, in some cases, retrieves proxyjacking software to divert network traffic for illicit gain.
- Systems infected with Perfctl may exhibit unusual spikes in CPU usage or slowdowns during idle periods, typical signs of hidden cryptocurrency mining.
The discovery of Perfctl emphasizes the growing threat to misconfigured and vulnerable Linux servers. Ensuring systems are up-to-date, implementing Role-Based Access Control (RBAC), and restricting unnecessary services are crucial steps to prevent such attacks.
Net Protector Cyber Security offers advanced endpoint protection, real-time malware detection, and server security solutions to safeguard critical infrastructures from sophisticated threats like Perfctl.
Comment(s)
Categories
- Other (43)
- Ransomware (154)
- Events and News (27)
- Features (45)
- Security (485)
- Tips (79)
- Google (28)
- Achievements (11)
- Products (35)
- Activation (7)
- Dealers (1)
- Bank Phishing (50)
- Malware Alerts (230)
- Cyber Attack (297)
- Data Backup (13)
- Data Breach (125)
- Phishing (165)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (71)
- Android Security (77)
- Knoweldgebase (38)
- Botnet (17)
- Updates (4)
- Alert (71)
- Hacking (70)
- Social Media (8)
- vulnerability (72)
- Hacker (38)
- Spyware (12)
- Windows (8)
- Microsoft (25)
- Uber (1)
- YouTube (1)
- Trojan (4)
- Website hacks (10)
- Paytm (1)
- Credit card scam (2)
- Telegram (3)
- RAT (8)
- Bug (3)
- Twitter (2)
- Facebook (8)
- Banking Trojan (9)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (2)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (3)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (39)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
- Fraud Protector (27)
Recent Posts
Archive
Tags
cybercrime
cybersecurity
cyber attack
phishing
phishing attacks
data breach
cyber threats
data theft
phishing attack
malware
android malware
credential theft
ransomware
cybersecurity threats
financial fraud
ransomeware
cyber fraud
social engineering
financial security
cyber security
#cybersecurity
data protection
cyberthreats
phishingattack
network security
cyber threat
identity theft
security vulnerabilities
cert-in
data stealing
ransomware attacks
cyber crime
phishing scam
online fraud
data security
ddos attack
cybersecurity awareness
critical vulnerability
india
phishing email
microsoft
digital safety
cyber attacks
twitter
ddos
cybercriminals
ransomware attack
trojan
malware attack
cyberattack