AI-Generated Malware in Panda Image Hides Persistent Linux Threat
Essential information
- Published
- 24/07/2025 19:44
- Modified
- 24/07/2025 20:42
- Tags
- 2025-07-24 ai-generated cryptomining koske linux polyglot-abuse rootkit
- Related entities
- 2 observables, 1 intrusion sets (apt), 1 malware, 1 others
Description
A sophisticated Linux malware campaign called Koske has been discovered, showing signs of AI-assisted development. The threat exploits misconfigured servers to install backdoors and download weaponized JPEG images containing malicious payloads. The malware uses polyglot file abuse to hide shellcode within images, deploys a userland rootkit, and employs various persistence techniques. It aggressively manipulates network settings to ensure command-and-control communication. The malware supports 18 different cryptocurrencies and adapts its mining strategy based on the host's capabilities. The code structure and adaptability suggest AI involvement in its creation, marking a concerning shift in malware development and posing significant challenges for cybersecurity defenses.