Perkons SA A.I CyberSecurity Scoring
Perkons SA
Company Information
Website:http://www.perkons.com
Employees number:344
Number of followers:17,001
NAICS:335
Industry Type:Appliances, Electrical, and Electronics Manufacturing
Homepage:perkons.com
Perkons SA Risk Score (AI oriented)
Between 700 and 749
Perkons SAAppliances, Electrical, and Electronics Manufacturing
Updated:
02/04/2026
02/04/2026
738/1000
Moderate
Ba
Perkons SA Global Score (TPRM)
xxxx
Perkons SAAppliances, Electrical, and Electronics Manufacturing
Score locked

Perkons SAModerate
Current Score
738Ba (MODERATE)
01000
1 incidents
-13 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
740
JULY 2026
740
JUNE 2026
740
MAY 2026
739
APRIL 2026
739
MARCH 2026
738
FEBRUARY 2026
738
JANUARY 2026
737
DECEMBER 2025
749
Cyber Attack
09 Dec 2025 • Perkons SA
Perkons SA: New PumaBot botnet brute forces SSH credentials to breach devices
PumaBot: Go-Based Linux Botnet Targeting IoT Devices via SSH Brute-Forcing
736
CRITICAL-13
PER1765238749
New Go-Based Botnet PumaBot Targets IoT Devices for Corporate Infiltration
Security researchers at Darktrace have uncovered PumaBot, a sophisticated Go-based Linux botnet that brute-forces SSH credentials on embedded IoT devices—particularly surveillance and traffic cameras—to deploy malicious payloads. Unlike traditional botnets that scan the internet broadly, PumaBot operates with precision, targeting specific IP addresses provided by its command-and-control (C2) server (ssh.ddos-cc.org).
The attack begins with the botnet receiving a curated list of target IPs from its C2. It then attempts to gain access via port 22 (SSH), checking for the string "Pumatronix"—a possible indicator of surveillance hardware from a specific vendor. Once inside, PumaBot verifies the device isn’t a honeypot by running uname -a, then establishes persistence by writing its binary (jierui) to /lib/redis and creating a systemd service (redis.service). It also injects its SSH key into authorized_keys to maintain access even if the primary infection is removed.
Active infections enable further compromise, including data exfiltration, payload delivery, and lateral movement. Darktrace observed payloads such as self-updating scripts, a PAM rootkit that replaces pam_unix.so to harvest SSH credentials, and a daemon (binary "1") that monitors and exfiltrates stolen data stored in con.txt before wiping the file to cover its tracks.
While the botnet’s scale remains unclear, its targeted approach suggests a focus on corporate network infiltration rather than low-level cybercrime like DDoS attacks. The discovery highlights the growing threat of IoT-focused malware designed to breach enterprise environments.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
749
OCTOBER 2025
749
SEPTEMBER 2025
749
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Perkons SA ??
What was Perkons SA's A.I Rankiteo Cyber Score in July 2026 ??
What was Perkons SA's A.I Rankiteo Cyber Score in June 2026 ??
What was Perkons SA's A.I Rankiteo Cyber Score in May 2026 ??
What was Perkons SA's A.I Rankiteo Cyber Score in April 2026 ??
What was Perkons SA's A.I Rankiteo Cyber Score in March 2026 ??
What was Perkons SA's A.I Rankiteo Cyber Score in February 2026 ??
What was Perkons SA's A.I Rankiteo Cyber Score in January 2026 ??
What was Perkons SA's A.I Rankiteo Cyber Score in December 2025 ??
What was Perkons SA's A.I Rankiteo Cyber Score in November 2025 ??
What was Perkons SA's A.I Rankiteo Cyber Score in October 2025 ??
What was Perkons SA's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Perkons SA's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Perkons SA ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Perkons SA's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?