Threat Actors Target Unpatched Linux Server Vulnerabilities With Malware Dubbed PERFCTL
A Linux malware dubbed “perfctl” was identified exploiting over 20000 types of
misconfigurations to target Linux servers worldwide.
Once compromised the malware remains dormant until the server is idle employing rootkits
to conceal its presence and using tactics to persist undetected.
It communicates internally via Unix sockets and externally via TOR and it deletes its binaries
post-execution to avoid detection.
Perfctls attack flow includes exploiting the Polkit vulnerability CVE-2021-4043 and/or
RocketMQ vulnerability CVE-2023-33246 for privilege escalation initial access and deploying
cryptominers to hijack resources.
SkyWatchSM Alert Legend
Warning
Active Threat
Malware
Ransomware
Phishing
Network/IOT
Glesec Information Sharing Protocol
GLESEC CYBER SECURITY INCIDENT REPORTS are in compliance with the U.S. Department of Homeland Security (DHS) Traffic-Light Protocol (TLP).
TLP-White
Disclosure is Not Limited.
TLP-Green
Limited Disclosure, Restricted Only to the Community.
TLP-Amber
Limited Disclosure, restricted to the Participant's Organization.
TLP-Red
Not for Disclosure, Restricted/ Classified - Only Shared with US DHS.
Discover Glesec.
Authority. Consistency.
Sign-up today for SkywatchSM Alerts.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.