216.73.216.6

AI-Generated Malware in Panda Image Hides Persistent Linux Threat

· Published 24/07/2025 19:44 · Modified 24/07/2025 20:42

Export JSON

Essential information

Published
24/07/2025 19:44
Modified
24/07/2025 20:42
Tags
2025-07-24 ai-generated cryptomining koske linux polyglot-abuse rootkit
Related entities
2 observables, 1 intrusion sets (apt), 1 malware, 1 others

Description

A sophisticated malware campaign called has been discovered, showing signs of AI-assisted development. The threat exploits misconfigured servers to install backdoors and download weaponized JPEG images containing malicious payloads. The malware uses polyglot file abuse to hide shellcode within images, deploys a userland , and employs various persistence techniques. It aggressively manipulates network settings to ensure command-and-control communication. The malware supports 18 different cryptocurrencies and adapts its mining strategy based on the host's capabilities. The code structure and adaptability suggest AI involvement in its creation, marking a concerning shift in malware development and posing significant challenges for cybersecurity defenses.

External references