are there any scripts or steps to 100% detect perfectl yet?
Also, it mentions that ~/.profile is modified (EDIT: and many others, actually), so IDS like AIDE, if operated correctly, should alert you on that. I don't see any mentions about attempts to circumvent locally run IDS. I wonder if/why malware author did not attempt any evasive actions here, given how much they try otherwise. Maybe cost/benefit ratio is too low?
IMHO, a simplest one is to check $PATH. If there are suspicious entries, like /bin/.local/bin, it's a sign of infection.
You can also check for presence of the specific files as mentioned close to the end of article.
I assume it starts by detecting a continuous 100% utilization of the cpu’s.