Skip to content

Comment on Perfctl: Stealthy malware targeting Linux serversparent

Comments

In all the attacks observed, the malware was used to run a cryptominer

I assume it starts by detecting a continuous 100% utilization of the cpu’s.

Supposedly it tones down it's activity while a user is logged in and waits for the machine to go idle. Another reason to have centralized performance monitoring.

Yes, but tools like htop show the average load over the last 15 min. So I assume that will show a high utilization.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.