Koske Linux Malware Hides in Panda Images and Shows Signs of AI-Assisted Development

Summary
Aqua Nautilus describes Koske, a Linux cryptomining malware campaign that uses image-embedded payloads, persistence mechanisms and a userland rootkit. Researchers say its modular code and adaptive behavior may indicate AI assistance.
Key points
- Attackers gained access through a misconfigured JupyterLab instance and downloaded malicious payloads disguised within JPEG files.
- The malware establishes persistence through shell configuration changes, cron jobs and systemd services.
- A rootkit using LD_PRELOAD hides files, directories and processes from user-space monitoring tools.
- Koske resets proxy settings, flushes iptables rules and changes DNS configuration to maintain connectivity and evade restrictions.
- It detects host hardware and can switch among miners for 18 cryptocurrencies.
- Aqua Nautilus says the code and adaptive connectivity behavior suggest possible AI assistance; the article does not establish that AI was used.
Article Details
- Attack Vectors
- The attackers gained initial access through a misconfigured JupyterLab instance.
- The attackers downloaded JPEG images with malicious payloads appended to them, then extracted and executed the appended content in memory.
- The payloads included a shell script and C code compiled into a userland rootkit.
- Koske downloaded cryptominers and selected CPU- or GPU-optimized miners based on host capabilities.
- Defensive Notes
- Monitor unauthorized changes to .bashrc and .bash_logout, unexpected systemd services, crontab changes, and DNS configuration rewrites.
- Investigate anomalous shell behavior and CPU or GPU resource spikes using runtime telemetry.
- Block execution of payloads embedded in image files and use drift prevention to detect rootkit injection into containers.
- Audit proxy abuse and mass egress testing; restrict outbound DNS and curl or wget access as appropriate.
- Use Aqua Trivy and runtime security policies to block suspicious binaries compiled at runtime.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 178[.]220[.]112[.]53 | Identified in the IOC table as the attacker's IP address and described as the origin of initial access. |
| MD5 | 2ed2e0e3d1ccfc20de48fa6bf49e6c89 | MD5 of the rootkit object file ccTltpHf.o. |
| MD5 | 305264d95d5056bc5de3a0b683bcd7eb | MD5 of the cryptominer binary cpuMinerTermux.koske. |
| MD5 | 63e613cab023c023d74e9dc8e0168e54 | MD5 of the rootkit binary hideproc.so. |
| MD5 | 6e9929b127afc5b4351ba3318e2178dc | MD5 of a ccminer binary. |
| MD5 | 76c5d978d6ef48af4350a12f238e48c4 | MD5 of the rootkit code file hideproc.c. |
| URL | hxxp[:]//tiny[.]cc/panda-v14 | Image download URL listed as an indicator for the payload-delivery attack. |
| URL | hxxps[:]//i[.]imgs[.]ovh/2025/07/17/DGlLc[.]jpeg | Image download URL listed as an indicator for the payload-delivery attack. |
| URL | hxxps[:]//i[.]imgs[.]ovh/2025/07/17/DmvmA[.]jpeg | Image download URL listed as an indicator for the payload-delivery attack. |
| URL | hxxps[:]//iili[.]io/FhFK3Eg[.]jpg | Image download URL listed as an indicator for the payload-delivery attack. |
| URL | hxxps[:]//k0ske[.]short[.]gy/panda_v14 | Image download URL listed as an indicator for the payload-delivery attack. |
MITRE ATT&CK
T1014 · RootkitA userland rootkit filters readdir() results to conceal files, directories, and processes associated with Koske.T1027.009 · Embedded PayloadsMalicious shell-script and rootkit payloads are appended to valid JPEG images and extracted after download.T1037.004 · RC ScriptsThe attackers modify /etc/rc.local to support execution at boot.T1053.003 · CronThe attackers schedule cron tasks at 30-minute intervals and on reboot.T1059.004 · Unix ShellAn appended shell-script payload executes in memory and uses system utilities to maintain execution.T1082 · System Information DiscoveryKoske evaluates host CPU and GPU capabilities before deploying optimized miners.T1496 · Resource HijackingKoske deploys cryptominers and switches between coins or mining pools when one fails.T1543.002 · Systemd ServiceThe attackers create systemd services, including the self-restarting shellkoske.service, for continued execution.T1546.004 · Unix Shell Configuration ModificationThe attackers edit .bashrc and .bash_logout to execute a custom .bashrc.koske script.T1562.004 · Disable or Modify System FirewallKoske flushes iptables rules while attempting to restore connectivity.T1574.006 · Dynamic Linker HijackingThe userland rootkit uses LD_PRELOAD or /etc/ld.so.preload to intercept readdir() calls.
Malware
Vendors
Products
Aqua PlatformThe Aqua Platform offers full lifecycle protection for cloud native workloads, with runtime defenses designed to detect and stop threats like Koske.Aqua Secure AIAs part of the platform, Aqua Secure AI extends these protections to AI-powered applications and infrastructure, helping teams monitor and mitigate emerging risks tied to large language models and AI-generated code.JupyterLabThe initial access is achieved by exploitation of a misconfiguration JupyterLab instance from a Serbian IP address178.220.112.53 origin.LinuxKoske, a sophisticated Linux threat, shows clear signs of AI-assisted development, likely with help from a large language model.