ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Linux Malware “Perfctl” Exploits Vulnerabilities (CVE-2023-33246) and Misconfigurations

Stealthy Malware Infects Thousands of Linux Machines

Kyle by Kyle
October 4, 2024
in Malware
Reading Time: 2 mins read
Prefctl Linux Malware CVE 2023 33246
Share on FacebookShare on Twitter

A sophisticated malware strain dubbed “Perfctl” has been discovered infecting thousands of Linux machines. Aqua Security security researchers revealed their findings on Thursday, highlighting the malware’s stealth capabilities and potential to exploit a wide range of misconfigurations.

Key Features of Perfctl

Perfctl, which has been active since at least 2021, stands out for several reasons:

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

  1. Exploitation of misconfigurations: It can take advantage of over 20,000 common misconfigurations, potentially putting millions of internet-connected machines at risk.
  2. CVE-2023-33246 vulnerability: The malware can exploit this critical vulnerability (rated 10/10 in severity) in Apache RocketMQ, a popular messaging and streaming platform for Linux.
  3. Stealth mechanisms: Perfctl employs various techniques to avoid detection, including:
    • Using rootkits to hide from the operating system and admin tools
    • Stopping easily detectable activities when a new user logs in
    • Communicating via Unix socket over TOR
    • Deleting its installation binary after execution
    • Manipulating the Linux process pcap_loop to prevent traffic recording
    • Suppressing error messages during execution
  4. Persistence: The malware ensures it remains on infected machines by modifying login scripts and copying itself to multiple locations.

Malicious Activities

Once installed, Perfctl engages in several harmful activities:

  1. Cryptocurrency mining: It uses the infected machine’s resources to mine cryptocurrency.
  2. Proxy-jacking: The malware turns the machine into a profit-generating proxy for paying customers to route their internet traffic.
  3. Backdoor installation: Researchers have observed Perfctl as a gateway for installing other malware families.

Infection Process

The malware’s infection process is complex and well-designed to evade detection:

  1. Initial exploit: Perfctl exploits vulnerabilities or misconfigurations to gain access.
  2. Payload download: The main payload is downloaded from a compromised server.
  3. Self-relocation: The malware copies itself to the /tmp directory and executes under a different name.
  4. Privilege escalation: It attempts to gain root access by exploiting CVE-2021-4043 in the Gpac multimedia framework.
  5. Component installation: Perfctl installs rootkits, modified Linux utilities, and mining software.

perfctl attack flow using CVE 2023 33246

Impact and Scope

Aqua Security researchers estimate that thousands of Linux machines are infected with Perfctl. The potential target pool is much larger, with millions of vulnerable machines connected to the internet.
Assaf Morag, Threat Intelligence Director at Aqua Security, stated, “Perfctl malware stands out as a significant threat due to its design, which enables it to evade detection while maintaining persistence on infected systems.”

Detection and Prevention

To detect Perfctl infections, users should look for:

  1. Unusual CPU usage spikes
  2. Sudden system slowdowns, especially during idle times
  3. Specific indicators of compromise are listed in Aqua Security’s report

To prevent infections:

  1. Install the patch for CVE-2023-33246
  2. Address the misconfigurations identified by Aqua Security
  3. Implement robust security measures and keep systems updated
Previous Post

More_eggs Malware Spread via Fake Resumes to HR Departments

Next Post

American Water Faces Cyber-Attack, Suspends Billing Operations

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.