Threat Actors Target Unpatched Linux Server Vulnerabilities With Malware Dubbed PERFCTL

skywatcg-alert-2

A Linux malware dubbed “perfctl” was identified exploiting over 20000 types of
misconfigurations to target Linux servers worldwide.
Once compromised the malware remains dormant until the server is idle employing rootkits
to conceal its presence and using tactics to persist undetected.
It communicates internally via Unix sockets and externally via TOR and it deletes its binaries
post-execution to avoid detection.
Perfctls attack flow includes exploiting the Polkit vulnerability CVE-2021-4043 and/or
RocketMQ vulnerability CVE-2023-33246 for privilege escalation initial access and deploying
cryptominers to hijack resources.

SkyWatchSM Alert Legend

  • small-bell

    Warning

  • active-threat0-lt-green

    Active Threat

  • malware-lt-green

    Malware

  • ransome-lt-green

    Ransomware

  • warning-green

    Phishing

  • file-green

    Network/IOT

Glesec Information Sharing Protocol

GLESEC CYBER SECURITY INCIDENT REPORTS are in compliance with the U.S. Department of Homeland Security (DHS) Traffic-Light Protocol (TLP).

  • TLP-White

    Disclosure is Not Limited.

  • TLP-Green

    Limited Disclosure, Restricted Only to the Community.

  • TLP-Amber

    Limited Disclosure, restricted to the Participant's Organization.

  • TLP-Red

    Not for Disclosure, Restricted/ Classified - Only Shared with US DHS.

Discover Glesec.

Authority. Consistency.

Sign-up today for SkywatchSM Alerts.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.