perfctl
Aliases: perfcc
- First seen
- 2018-04-10 00:00:00
- Malware type
- trojan, keylogger
- Family
- Malware family
- Last IoC activity
- 2026-07-18 13:57:02
- Profile updated
- 2026-07-07 14:28:29
Targeted industries: government-and-public-sector financial-services
Targeted regions: country_code:us country_code:gb
Context
Perfctl, also known as perfcc, is a trojan malware that specifically targets government and financial sectors. It has capabilities of logging keystrokes and exfiltrating sensitive data from compromised systems.
Detection coverage
- 2 YARA rules
Detection rules
- SIGNATURE_BASE_MAL_EXPL_Perfctl_Oct24 (yara-rule)
- SIGNATURE_BASE_MAL_LNX_Perfctl_Oct24 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Perfctl (report)
- aquasec.com — Perfctl A Stealthy Malware Targeting Millions Of Linux Servers (report)
- cadosecurity.com — From Automation To Exploitation The Growing Misuse Of Selenium Grid For Cryptomining And Proxyjacking (report)