Skip to content

Comment on Perfctl: Stealthy malware targeting Linux servers

Comments

A lot of focus on the malware itself, but not so much on the misconfigurations and vulnerabilities which enable it. Would love to see that list. Other than that, the evasion techniques look pretty traditional.

And of course the privilege escalation is done by a polkit vulnerability...

It seems to be a RocketMQ vuln; it's described further down the page.

Also more interested in what the misconfigs are.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.