s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-elf.perfctl

📛 Threat Title

Malware family: perfctl

Category: perfctl First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.perfctl`. Printable name: perfctl. Aliases: perfcc.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.perfctl VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.perfctl

IOC database

Type
domain
Value
elf.perfctl
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.perfctl

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.perfctl

References (1)

Remediations (10)

  • web:beljic.dev

    A practical breakdown of the perfctl Linux malware campaign, how it abuses weak server posture after initial access, and what to harden on Laravel, PHP, and general Linux hosts to reduce the chance of the same class of compromise.

  • web:linuxsecurity.com

    Perfctl uses a rootkit to hide its processes and activities from system monitors and administrators, as well as fileless attack methods aimed at operating solely within memory, which help avoid traditional file-based antivirus and detection tools. Named " perfctl ," the malware's name seeks to appear as a legitimate system process.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the perfctl malware family including references, samples and yara signatures.

  • web:socradar.io

    Remediation Steps for Perfctl Malware To defend against Perfctl , a multi-layered approach combining monitoring, system hardening, and proactive threat intelligence is essential.

  • web:www.aquasec.com

    The name perfctl comes from the cryptominer process that drains the system's resources, causing significant issues for many Linux developers. By combining "perf" (a Linux performance monitoring tool) with "ctl" (commonly used to indicate control in command-line tools), the malware authors crafted a name that appears legitimate.

  • web:www.bleepingcomputer.com

    A Linux malware named " perfctl " has been targeting Linux servers and workstations for at least three years, remaining largely undetected through high levels of evasion and the use of rootkits.

  • web:www.csoonline.com

    Exploiting a catalog of 20,000 misconfigurations to infect Linux servers, the cryptomining malware has gone largely undetected through use of process masquerading but appears capable of more.

  • web:www.helpnetsecurity.com

    Thousands of Linux systems are likely infected with the highly elusive and persistent " perfctl " (or "perfcc") cryptomining malware .

  • web:www.securityweek.com

    Researchers at Aqua Security are raising the alarm for a newly discovered malware family targeting Linux systems to establish persistent access and hijack resources for cryptocurrency mining. The malware , called perfctl , appears to exploit over 20,000 types of misconfigurations and known ...

  • web:www.wired.com

    Stealthy Malware Has Infected Thousands of Linux Systems for Years Perfctl malware is hard to detect, persists after reboots, and can perform a breadth of malicious activities.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.