216.73.216.226

From Perfctl to InfoStealer

· Published 09/10/2024 14:15 · Modified 09/10/2024 15:35

Export JSON

Essential information

Published
09/10/2024 14:15
Modified
09/10/2024 15:35
Tags
2024-10-09 cryptominer data exfiltration linux malware perfctl rootkit stealth trufflehog
Related entities
3 observables, 20 techniques (mitre), 1 malware

Description

A new stealthy called has been analyzed. The runs two processes: and a disguised process mimicking known processes. It uses Tor for external communications and local sockets for inter-process communication. After 30 minutes, the attacker drops scripts to footprint the host, search for files/credentials, and exfiltrate data. , a credentials scanner, is downloaded and used. The attacker searches for interesting files using a large list of regular expressions, inspects processes and their memory, and checks for Docker containers. The replicates itself by creating new binaries with different names. Collected data is archived and exfiltrated. This demonstrates that seemingly simple cryptominers can lead to data theft and further system compromise.

External references