perfctl

Aliases: perfcc

First seen
2018-04-10 00:00:00
Malware type
trojan, keylogger
Family
Malware family
Last IoC activity
2026-07-18 13:57:02
Profile updated
2026-07-07 14:28:29

Targeted industries: government-and-public-sector financial-services

Targeted regions: country_code:us country_code:gb

Context

Perfctl, also known as perfcc, is a trojan malware that specifically targets government and financial sectors. It has capabilities of logging keystrokes and exfiltrating sensitive data from compromised systems.

Detection coverage

  • 2 YARA rules

Detection rules

  • SIGNATURE_BASE_MAL_EXPL_Perfctl_Oct24 (yara-rule)
  • SIGNATURE_BASE_MAL_LNX_Perfctl_Oct24 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Perfctl (report)
  • aquasec.com — Perfctl A Stealthy Malware Targeting Millions Of Linux Servers (report)
  • cadosecurity.com — From Automation To Exploitation The Growing Misuse Of Selenium Grid For Cryptomining And Proxyjacking (report)

External references