#Perfctl
3+ YEARS of stealth! We uncovered new tactics used by the perfctl malware, including a userland rootkit & an SSH backdoor (a single SPACE in /etc/passwd!). More insights: blog.exatrack.com/Perfctl-usin... #cybersecurity #threat_hunting #linux #infosec #perfctl #rootkit #ssh #exatrack
Perfctl malware exploiting exposed Portainer agent and using new SSH persistenceExaTrack
blog.exatrack.com
December 17, 2024 at 10:02 AM
perfctl: A Stealthy Malware Targeting Millions of #Linux Servers www.aquasec.com/blog/perfctl... Stay safe, my friends!
perfctl: A Stealthy Malware Targeting Millions of Linux Servers
Perfctl is particularly elusive and persistent malware employing several sophisticated techniques
www.aquasec.com
October 4, 2024 at 8:58 AM
勝手にCPUを100%使って仮想通貨をマイニングするLinux向けマルウェア「perfctl」が発見される、ログイン時は活動を停止するので発見困難で数百万台のサーバーが標的になった可能性
https://gigazine.net/news/20241007-perfctl-malware-linux/
勝手にCPUを100%使って仮想通貨をマイニングするLinux向けマルウェア「perfctl」が発見される、ログイン時は活動を停止するので発見困難で数百万台のサーバーが標的になった可能性
「perfctl」と呼ばれるLinux向けマルウェアが3年以上前から活動していたことが明らかになりました。perfctlはCPUを100%使って仮想通貨「Monero」をマイニングするマルウェアで、数百万台のサーバーが標的となり数千台のサーバーが実際に被害を受けたと推測されています。
gigazine.net
October 7, 2024 at 4:27 AM
The malware is installed by exploiting more than 20,000 common misconfigurations, a capability that may make millions of machines connected to the Internet potential targets.
Thousands of Linux systems infected by stealthy malware since 2021
The ability to remain installed and undetected makes Perfctl hard to fight.
arstechnica.com
October 4, 2024 at 3:15 PM
Heads up, linuxers
Thousands of Linux systems infected by stealthy malware since 2021
The ability to remain installed and undetected makes Perfctl hard to fight.
arstechnica.com
October 4, 2024 at 3:21 PM
perfctl: A Stealthy Malware Targeting Millions of #Linux Servers www.aquasec.com/blog/perfctl... #Security
perfctl: A Stealthy Malware Targeting Millions of Linux Servers
Perfctl is particularly elusive and persistent malware employing several sophisticated techniques
www.aquasec.com
October 4, 2024 at 11:14 AM
Perfctl malware strikes again as crypto-crooks target Docker Remote API servers
Perfctl malware strikes again as crypto-crooks target Docker Remote API servers
Attacks on unprotected servers reach 'critical level' An unknown attacker is abusing exposed Docker Remote API servers to deploy perfctl cryptomining malware on victims' systems, according to Trend Micro researchers.…
dlvr.it
October 24, 2024 at 2:33 AM
勝手にCPUを100%使って仮想通貨をマイニングするLinux向けマルウェア「perfctl」が発見される、ログイン時は活動を停止するので発見困難で数百万台のサーバーが標的になった可能性
https://gigazine.net/news/20241007-perfctl-malware-linux/
勝手にCPUを100%使って仮想通貨をマイニングするLinux向けマルウェア「perfctl」が発見される、ログイン時は活動を停止するので発見困難で数百万台のサーバーが標的になった可能性
「perfctl」と呼ばれるLinux向けマルウェアが3年以上前から活動していたことが明らかになりました。perfctlはCPUを100%使って仮想通貨「Monero」をマイニングするマルウェアで、数百万台のサーバーが標的となり数千台のサーバーが実際に被害を受けたと推測されています。
gigazine.net
October 7, 2024 at 5:35 AM
Researchers say a Linux malware named "perfctl" has been targeting Linux servers to mine the hard-to-trace Monero cryptocurrency for at least three years (Bill Toulas/BleepingComputer)

Main Link | Techmeme Permalink
October 4, 2024 at 3:05 PM
Happy Thursday! Enjoy this well-written deep dive into a fascinating bit of Linux malware. I can't wait to get my hands on a sample!

www.aquasec.com/blog...
perfctl: A Stealthy Malware Targeting Millions of Linux Servers
Perfctl is particularly elusive and persistent malware employing several sophisticated techniques
www.aquasec.com
October 3, 2024 at 2:02 PM
"Thousands of Linux systems infected by stealthy malware since 2021

The ability to remain installed and undetected makes Perfctl hard to fight"
October 4, 2024 at 3:22 PM
'locate -i perfctl' should find it.
Yes Definitely GIF
ALT: Yes Definitely GIF
media.tenor.com
October 4, 2024 at 3:38 PM
Attacks on unprotected servers reach 'critical level'
Perfctl malware strikes again via Docker Remote API servers
Attacks on unprotected servers reach 'critical level'
www.theregister.com
October 24, 2024 at 3:34 AM
勝手にCPUを100%使って仮想通貨をマイニングするLinux向けマルウェア「perfctl」が発見される、ログイン時は活動を停止するので発見困難で数百万台のサーバーが標的になった可能性 - GIGAZINE
gigazine.net/news/2024100...
October 7, 2024 at 1:23 PM
New #Perfctl #Malware Attacking Millions of #Linux #Servers

potatosecuritynews.com/perfctl-malw... #potatosecurity
October 6, 2024 at 3:15 AM
Perfctl malware is hard to detect, persists after reboots, and can perform a breadth of malicious activities. www.wired.com/story/perfct...
Stealthy Malware Has Infected Thousands of Linux Systems for Years
Perfctl malware is hard to detect, persists after reboots, and can perform a breadth of malicious activities.
www.wired.com
October 6, 2024 at 12:27 PM
【気になったニュース🌞】

🔵Linux向けマルウェア「perfctl」が発見される!🔵
◯勝手にCPUを100%使って、仮想通貨をマイニング⛏️
◯ログイン時は活動停止→発見困難🕵️
◯「競合マルウェア削除機能」も実装⚔️
◯数百万台のサーバが標的になっている可能性🎯

サーバ管理者のみなさん、
勝手にマイニングに使われてませんか?🤔

gigazine.net/news/2024100...
勝手にCPUを100%使って仮想通貨をマイニングするLinux向けマルウェア「perfctl」が発見される、ログイン時は活動を停止するので発見困難で数百万台のサーバーが標的になった可能性
「perfctl」と呼ばれるLinux向けマルウェアが3年以上前から活動していたことが明らかになりました。perfctlはCPUを100%使って仮想通貨「Monero」をマイニングするマルウェアで、数百万台のサーバーが標的となり数千台のサーバーが実際に被害を受けたと推測されています。
gigazine.net
October 8, 2024 at 12:54 AM
Attackers Target Exposed Docker Remote API Servers With perfctl Malware https://buff.ly/4dWuCLG
Attackers Target Exposed Docker Remote API Servers With perfctl Malware
Business
buff.ly
October 23, 2024 at 3:12 AM