Proxyjacking

Malware updated a month ago (2024-11-29T13:56:06.815Z)
Download STIX
Preview STIX
Proxyjacking is a form of malware that targets misconfigured Linux servers to deploy cryptocurrency miners and proxyjacking software. This malicious software, known as perfctl, has been terrorizing Linux servers worldwide for years, infecting thousands of victims by hijacking their IP addresses for personal use or selling it to other cybercriminals. Despite the primary goal being to run cryptominers, experts warn that it also executes proxyjacking software, which can disrupt operations, steal personal information, or hold data hostage for ransom. Perfctl malware hides its loud activities such as cryptomining and proxyjacking, making it difficult to detect. It cancels any containers running on the node to install a Docker container to handle the proxyjacking process. Once everything is in place, the attacker can exit the network without leaving a trace. Not only does this malware enable attackers to earn money through cryptomining and proxyjacking, but it also allows them to steal secrets and potentially sell access to servers related to big companies in the cyber underground. Researchers have warned those running Linux servers to take immediate steps to protect their environments from perfctl and other fileless malware. Mitigation strategies include monitoring for suspicious downloads, emails, or websites that could serve as entry points for the malware. The threat posed by perfctl underscores the importance of maintaining up-to-date security measures and configurations, particularly for Linux servers which have been specifically targeted by this ongoing campaign.
Description last updated: 2024-10-17T12:21:28.100Z
What's your take? (Question 1 of 3)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Proxy
Malware
Linux
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Perfctl Malware is associated with Proxyjacking. Perfctl is a type of malware, a malicious software designed to exploit and damage computer systems. This harmful program can infiltrate your system via suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside the system, perfctl has the potential to steal personal informis related to
2
Source Document References
Information about the Proxyjacking Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more