By combining elements from standard Linux tools like “perf” (a performance monitoring tool) and “ctl” (indicating control), the malware authors have crafted a seemingly innocuous name that masks its malicious intent. Researchers have uncovered a sophisticated Linux malware, dubbed “perfctl,” actively targeting millions of Linux servers worldwide. GBHackers on Security is a top cybersecurity news platform, delivering up-to-date coverage on breaches, emerging threats, malware, vulnerabilities, and global cyber incidents. As perfctl evolves, staying informed about its tactics and applying proactive security measures are crucial for protecting Linux servers. Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world. This malicious software exploits over 20,000 types of server misconfigurations, posing a significant threat to any Linux server connected to the internet. The perfctl malware has been a growing concern in developer forums and online communities for the past few years. In many cases, perfctl has been used to run cryptominers, draining system resources and causing performance issues. The malware deploys a Monero cryptominer (XMRIG), which consumes significant CPU resources, leading to system slowdowns. According to the Aqua Nautilus reports, Perfctl is designed with multiple execution layers to ensure persistence and evade detection. To mitigate this threat, it is essential to regularly patch vulnerabilities, restrict file execution in writable directories, and deploy advanced anti-malware solutions. It has been linked to numerous incidents involving compromised Linux servers. The malware’s name derives from its ability to blend in with legitimate system processes, making it harder for administrators to identify. Initially named “httpd,” this payload copies itself into various locations on the disk, using deceptive names to avoid detection.
This Cyber News was published on gbhackers.com. Publication date: Fri, 04 Oct 2024 07:13:06 +0000