icon

Digital safety starts here for both commercial and personal Use...

Defend Your Business Against the Latest WNY Cyber Threats We offer Safe, Secure and Affordable Solutions for your Business and Personal Networks and Devices.



WNYCyber is there to help you to choose the best service providers in Western New York... We DO NOT provide the services ourselves, as we are Internet Programmers who have to deak daily with Cyber Threats... (Ugghhh)... So we know what it's like and what it takes to protect OUR and OUR CUSTOMERS DATA... We built this Website to help steer you to those that can give you the best service at realistic and non-inflated prices. We do charge or collect any fees.

New Perfctl Malware Targets Linux Servers for Cryptocurrency Mining and Proxyjacking

Summary:
Linux servers are under threat from a stealthy malware known as "perfctl," aimed at running cryptocurrency mining and proxyjacking software. This malware employs advanced evasion tactics, remaining inactive during user activity and deleting its own files to avoid detection. It exploits a vulnerability in Polkit (CVE-2021-4043) to gain root access and install the miner. The name "perfctl" is a deliberate attempt to mimic legitimate system processes. The attack typically involves exploiting vulnerable Apache RocketMQ instances to deliver the malware. Once activated, perfctl hides itself by copying to different locations and may also download additional proxyjacking tools from remote servers.

Security Officer Comments:
The perfctl malware campaign illustrates the growing complexity of cyber threats targeting Linux environments, especially those accessible online. Its ability to disguise itself as legitimate activity poses significant challenges for security teams in identifying and mitigating such threats.

Suggested Corrections:
To mitigate the risks associated with perfctl, organizations should implement several key strategies: regularly update all systems and software to address known vulnerabilities.

Link(s):
https://thehackernews.com/2024/10/new-perfctl-malware-targets-linux.html