major way to detect malware first top and see if any process use lot of cpu

  1. cat /proc/pid/pwd to see which dir it run in and see any suspicious files in it