/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers say Linux malware “perfctl” has been targeting millions of Linux servers to mine the hard-to-trace Monero cryptocurrency for at least three years

A Linux malware named “perfctl” has been targeting Linux servers and workstations for at least three years …

BleepingComputer Bill Toulas

Context & Ripple Effects

Perfctl extends a documented pattern of cryptomining campaigns aimed at server infrastructure: a Golang-based XMRig worm targeting Windows and Linux servers was reported in 2021, while Shikitega’s stealthy Linux-server and IoT infections showed that Linux-focused malware was evolving beyond commodity attacks. The reported multi-year duration matters because it suggests compromised Linux estates can remain useful to operators well after initial access.

First-order effects

  • Affected Linux server and workstation operators face unauthorized CPU consumption and potentially degraded workload performance while perfctl mines Monero.
  • Security teams need to treat long-running cryptomining as a persistence and visibility problem, not only as an isolated resource-abuse incident.

Second-order effects

  • Hosting and infrastructure operators may face higher investigation and remediation costs as they distinguish legitimate compute-intensive workloads from concealed mining activity.
  • The campaign reinforces demand for endpoint, workload, and server monitoring that can identify abnormal resource use across Linux fleets.

Third-order effects

  • If long-lived Linux mining campaigns remain viable, attackers will continue to favor infrastructure environments where high compute capacity and uneven monitoring make persistence valuable.
  • Cryptomining malware is becoming a durable operational-security issue for server operators, with attacker economics tied as much to sustained access as to initial exploitation.

The trend: Linux infrastructure is an increasingly sustained target for stealthy, resource-monetizing malware rather than only short-lived opportunistic attacks.

Discussion

  • @marypcbuk.bsky.social Scary Mary Branscombe on bluesky
    I assume we're all past the 'but Linux doesn't get malware' stage of naivety by now [embedded post]