What's new
Christian Community Forum

Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!

Stealthy Malware Has Infected Thousands of Linux Systems for Years

Tall Timbers

Imperfect but forgiven
Staff member
Thousands of machines running Linux have been infected by a malware strain that’s notable for its stealth, the number of misconfigurations it can exploit, and the breadth of malicious activities it can perform, researchers reported Thursday.

The malware has been circulating since at least 2021. It gets installed by exploiting more than 20,000 common misconfigurations, a capability that may make millions of machines connected to the internet potential targets, researchers from Aqua Security said. It can also exploit CVE-2023-33426, a vulnerability with a severity rating of 10 out of 10 that was patched last year in Apache RocketMQ, a messaging and streaming platform that’s found on many Linux machines.

Perfctl Storm
The researchers are calling the malware Perfctl, the name of a malicious component that surreptitiously mines cryptocurrency. The unknown developers of the malware gave the process a name that combines the perf Linux monitoring tool and ctl, an abbreviation commonly used with command line tools. A signature characteristic of Perfctl is its use of process and file names that are identical or similar to those commonly found in Linux environments. The naming convention is one of the many ways the malware attempts to escape notice of infected users.


Wired has a paywall but you can get around it by deleting all Wired cookies then reloading the page you want to read.
 
It was only a matter of time as most hackers use some version of Linux most notably Kali with all the built in hacking tools. Over time as people wanted to leave MS because of MS10 and now MS11, a lot of them are going to some mild form of Linux, Mint, and the many Debian as well as Ubuntu versions for new users made fairly easy to learn and use. I am guessing users of Kali, Parrot, are not likely facing such problems as most users who use those version OS know how to configure better than the average bear. But it just goes to show you no one is truely safe online anymore. Now add all the AI out there that is now being used to solve infiltration struggles there will come a day when no OS or software package or app will be safe.
 
Back
Top