Researchers reported that the perfctl malware campaign has compromised large numbers of internet-facing Linux servers by exploiting vulnerable or misconfigured systems and then establishing deep persistence. Aqua Security said the malware has operated for several years, using CVE-2023-33246 in Apache RocketMQ for initial access and attempting CVE-2021-4034 in Polkit for privilege escalation. Once deployed, perfctl deletes its original binary, disguises itself as legitimate processes, communicates locally over Unix sockets, and routes external traffic through Tor to reduce detection.
The campaign primarily monetizes access through XMRIG Monero mining, while some infected hosts were also used for proxyjacking via services including Bitping, Earn.fm, Speedshare, and Repocket. Aqua said the malware maintains stealth with LD_PRELOAD rootkits, trojanized userland tools, modified profile scripts, and watchdog components such as wizlmsh, and it even suppresses noisy activity when users log in. Separate reporting on the abuse of Selenium Grid infrastructure for cryptomining and proxyjacking points to a broader trend of attackers repurposing exposed Linux and cloud services for covert resource theft and bandwidth monetization.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Aqua Nautilus disclosed technical details of perfctl, including observed initial access via CVE-2023-33246 in RocketMQ, attempted privilege escalation via CVE-2021-4034 in Polkit, use of LD_PRELOAD rootkits and trojanized utilities for stealth, and persistence through modified profile scripts and watchdog components. Aqua also reported that all observed attacks deployed an XMRIG-based Monero miner, with some infections additionally running proxy-jacking software tied to Bitping, Earn.fm, Speedshare, and Repocket.
Aqua Nautilus reported that the perfctl malware campaign had been active for roughly 3-4 years, scanning for more than 20,000 types of misconfigurations and exploiting vulnerable or misconfigured internet-facing Linux servers at scale. The researchers assessed that the campaign likely targeted millions of Linux servers worldwide and may have resulted in thousands of victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.