Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
It attempts to exploit the Polkit vulnerability (CVE-2021-4034) to escalate privileges... The malware contains an exploit to CVE-2021-4034, which it is trying to run in order to gain root privilege on the server. | The community has widely referred to it as the “perfctl malware,” and we have adopted this name. ... It utilizes rootkits to hide its presence ... It opens a backdoor on the server and listens for TOR communications ... It attempts to exploit the Polkit vulnerability (CVE-2021-4034) to escalate privileges.
Appendix 1: Initial Access CVE-2023-33246 is a vulnerability found in RocketMQ... The initial access was gained via this vulnerability (CVE-2023-33246), led to download and execution of the shell script rconf. | The community has widely referred to it as the “perfctl malware,” and we have adopted this name. ... It utilizes rootkits to hide its presence ... It opens a backdoor on the server and listens for TOR communications ... It attempts to exploit the Polkit vulnerability (CVE-2021-4034) to escalate privileges.
44 distinct techniques documented for this family, organized by ATT&CK tactic.
use services and cron job for persistence ... /etc/cron.d/perfclean used in main.CronSystemWideCrond
The initial access was gained via this vulnerability (CVE-2023-33246), led to download and execution of the shell script rconf.
the now relatively documented perfctl malware ... is able to hide many of its actions via a LD_PRELOAD library injection
The rootkit is using LD_PRELOAD to load itself before other libraries.
The attacker modifies the ~/.profile script, which sets up the environment during user login. This script is designed to execute the malware first, followed by the legitimate workload expected to run on the server.
use services and cron job for persistence ... /etc/cron.d/perfclean used in main.CronSystemWideCrond
This allows SSH access while appearing to have a “nologin” shell at first glance.
By placing their public keys in the authorized_keys file, attackers can gain access without requiring further authentication if the private key is in their possession.
It also exploits exposed Portainer agents ... It may backdoor existing account on the server to enable SSH access
If you try downloading the .php file without a specific user agent, you will receive a file with the integer 1. But if you use the correct user agent it will drop the malware.
The binary wizlmsh is dropped to /usr/bin ... It is a very small binary (12kb), that runs as a service in the background.
The attacker modifies the ~/.profile script, which sets up the environment during user login. This script is designed to execute the malware first, followed by the legitimate workload expected to run on the server.
use services and cron job for persistence ... /etc/cron.d/perfclean used in main.CronSystemWideCrond
This allows SSH access while appearing to have a “nologin” shell at first glance.
By placing their public keys in the authorized_keys file, attackers can gain access without requiring further authentication if the private key is in their possession.
The binary wizlmsh is dropped to /usr/bin ... It is a very small binary (12kb), that runs as a service in the background.
/.config/cron/perfcc used in main.AddToProfile
This technique is called ‘process masquerading’ or ‘process replacement’ ... The new Httpd binary is now saved in the /tmp directory under the name of the process that executed it sh in our case.
Make a copy of /bin/dash as /usr/sbin/nologin (with a trailing space) ... Add a space at the end of news line in /etc/passwd
After execution, it deletes its binary and continues to run quietly in the background as a service.
This allows SSH access while appearing to have a “nologin” shell at first glance.
If you try downloading the .php file without a specific user agent, you will receive a file with the integer 1. But if you use the correct user agent it will drop the malware.
They drop a few legitimate utilities such as ldd. These utilities were modified to hide specific attack elements.
the script continues with a simple if condition, that will ensure that the targeted attacked server OS architecture is x86_64.
The rootkit has several purposes. One of the main purposes is to hook various functions and modify their functionality.
the main payload is downloaded from an HTTP server controlled by the attacker.
It utilizes Unix socket for internal communication and TOR for external communication.
As part of its command-and-control operation, the malware opens a Unix socket
After exploiting a vulnerability ... the main payload is downloaded from an HTTP server controlled by the attacker.
65 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux malware/backdoor referenced in connection with an incident response where attackers used a trailing-space shell trick for persistence and SSH access while appearing to use a nologin shell.
Malware referenced in connection with abuse of SSH authorized_keys persistence via system accounts.
Linux malware described as designed to evade detection and compromise large numbers of servers.
Linux malware used to monetize compromised servers through cryptojacking and proxyjacking. It abuses exposed services for initial access, establishes persistence via cron/services, deploys a miner, installs an LD_PRELOAD userland rootkit for stealth, can steal credentials and session data, and may backdoor accounts for SSH access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.