HomeSecurityLinux malware "perfctl" is used for cryptomining

Linux malware “perfctl” used for cryptomining

Security researchers have discovered a Linux malware named “perfctl”that has been targeting Linux servers and workstations (for cryptomining) for at least three years, going unnoticed.

perfctl Linux malware cryptomining

Aqua Nautilus researchers discovered perfctl and believe the malware may have infected thousands of Linux servers , based on victims' reports on online forums. These reports contain breach indicators that are exclusively related to perfctl activity.

According to Aqua Nautilus, perfctl's primary purpose is cryptomining. It uses compromised servers to mine Monero. However, it could be used for other malicious purposes as well.

See also: Linux malware gang exploits Oracle Weblogic for cryptocurrency mining

How is the attack carried out?

Aqua Nautilus believes that attackers are exploiting misconfigurations (e.g. publicly accessible files with credentials, etc.) or exposed secrets to compromise Linux servers.

Researchers also observed that the vulnerability CVE-2023-33246 is being exploited, which affects Apache RocketMQ 5.1.0 and earlier versions and allows remote command execution. Hackers exploiting CVE-2021-4034 (PwnKit), a privilege escalation vulnerability in Polkit.

Once the initial access is made, the obfuscated payload, called “httpd”, is downloaded from the attacker’s server and executed. It then copies itself to the /tmp directory under the name “sh” and deletes the original binary.

The new process is given the same name (“sh”), to hide within the normal Linux system operations.

See also: sedexp: A Linux malware that remained hidden for two years

Additional copies are also created in other system locations, such as “/root/.config”, “/usr/bin/” and “usr/lib” to ensure persistence in the event of a cleanup.

Linux malware "perfctl" is used for cryptomining

Main mechanisms of operation and escape

Upon startup, the Linux malware perfctl opens a Unix socket for internal communications and establishes an encrypted channel with the attacker's servers via TOR.

It then installs a rootkit named “libgcwrap.so.” This hooks into various systemto modify authentication mechanisms and interfere with network traffic to evade detection.

It then deploys additional userland rootkits, replacing the ldd, top, crontab, and lsof utilities with trojanized versions.

Finally, an XMRIG miner for cryptomining, using the server's CPU resources. The cryptominer communicates with the mining pools via TOR , so network traffic is hidden and profits cannot be traced.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Most users become aware of the infection when they notice that their CPU is being used at 100% due to cryptocurrency mining. However, the Linux malware perfctl effectively evades detection. It runs its mining activities until a user logs in to the server. It then stops immediately and starts again when the server goes idle again.

Since malware modifies and replaces legitimate files , you may need to perform a clean install to ensure anything malicious is removed.

See also: Linux malware AcidPour targets Ukraine

Additionally, Aqua Nautilus suggests several ways to detect and stop Linux malware perfctl, which fall into four main categories: system monitoring, network traffic analysis, monitoring file and process integrity

Regarding detection, Aqua Nautilus suggests the following:

  • Regularly check the /tmp, /usr, and /root directories for suspicious binaries masquerading as legitimate system files.
  • Monitor CPU usage.
  • Examine ~/.profile, ~/.bashrc, and /etc/ld.so.preload for unauthorized modifications.
  • Capture and analyze network traffic for TOR-based connections to external IPs.
  • Look for outgoing connections to known cryptomining pools or proxy-jacking services.
  • Add the IP addresses, found in the IoC section of the report, to a block list.
  • Fix all potential vulnerabilities by applying security updates.
Linux malware "perfctl" is used for cryptomining

Protection from Linux malware

Linux malware protection, such as perfctl, involves many best practices to ensure system integrity and security. First and foremost, regularly updating the operating system and installed software can patch vulnerabilities that malware might exploit. Additionally, using a strong firewall helps monitor and control incoming and outgoing network traffic, providing an additional layer of defense.

Users should also be cautious when downloading software from untrusted sources and use package managers to install applications, as these tools often verify the integrity of the software. Integrating antivirus solutions, specifically designed for Linux, can also help detect and mitigate potential threats, ensuring a safer computing environment.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS