Researchers say Linux malware “perfctl” has been targeting millions of Linux servers to mine the hard-to-trace Monero cryptocurrency for at least three years
A Linux malware named “perfctl” has been targeting Linux servers and workstations for at least three years …
Context & Ripple Effects
Perfctl extends a documented pattern of cryptomining campaigns aimed at server infrastructure: a Golang-based XMRig worm targeting Windows and Linux servers was reported in 2021, while Shikitega’s stealthy Linux-server and IoT infections showed that Linux-focused malware was evolving beyond commodity attacks. The reported multi-year duration matters because it suggests compromised Linux estates can remain useful to operators well after initial access.
First-order effects
- Affected Linux server and workstation operators face unauthorized CPU consumption and potentially degraded workload performance while perfctl mines Monero.
- Security teams need to treat long-running cryptomining as a persistence and visibility problem, not only as an isolated resource-abuse incident.
Second-order effects
- Hosting and infrastructure operators may face higher investigation and remediation costs as they distinguish legitimate compute-intensive workloads from concealed mining activity.
- The campaign reinforces demand for endpoint, workload, and server monitoring that can identify abnormal resource use across Linux fleets.
Third-order effects
- If long-lived Linux mining campaigns remain viable, attackers will continue to favor infrastructure environments where high compute capacity and uneven monitoring make persistence valuable.
- Cryptomining malware is becoming a durable operational-security issue for server operators, with attacker economics tied as much to sustained access as to initial exploitation.
The trend: Linux infrastructure is an increasingly sustained target for stealthy, resource-monetizing malware rather than only short-lived opportunistic attacks.