Koske Linux Malware Hides in Panda Images and Shows Signs of AI-Assisted Development

· Original article ↗

Summary

Aqua Nautilus describes Koske, a Linux cryptomining malware campaign that uses image-embedded payloads, persistence mechanisms and a userland rootkit. Researchers say its modular code and adaptive behavior may indicate AI assistance.

Key points

  • Attackers gained access through a misconfigured JupyterLab instance and downloaded malicious payloads disguised within JPEG files.
  • The malware establishes persistence through shell configuration changes, cron jobs and systemd services.
  • A rootkit using LD_PRELOAD hides files, directories and processes from user-space monitoring tools.
  • Koske resets proxy settings, flushes iptables rules and changes DNS configuration to maintain connectivity and evade restrictions.
  • It detects host hardware and can switch among miners for 18 cryptocurrencies.
  • Aqua Nautilus says the code and adaptive connectivity behavior suggest possible AI assistance; the article does not establish that AI was used.

Article Details

Attack Vectors
  • The attackers gained initial access through a misconfigured JupyterLab instance.
  • The attackers downloaded JPEG images with malicious payloads appended to them, then extracted and executed the appended content in memory.
  • The payloads included a shell script and C code compiled into a userland rootkit.
  • Koske downloaded cryptominers and selected CPU- or GPU-optimized miners based on host capabilities.
Defensive Notes
  • Monitor unauthorized changes to .bashrc and .bash_logout, unexpected systemd services, crontab changes, and DNS configuration rewrites.
  • Investigate anomalous shell behavior and CPU or GPU resource spikes using runtime telemetry.
  • Block execution of payloads embedded in image files and use drift prevention to detect rootkit injection into containers.
  • Audit proxy abuse and mass egress testing; restrict outbound DNS and curl or wget access as appropriate.
  • Use Aqua Trivy and runtime security policies to block suspicious binaries compiled at runtime.

Indicators of compromise

TypeIndicatorContext
IPV4178[.]220[.]112[.]53Identified in the IOC table as the attacker's IP address and described as the origin of initial access.
MD52ed2e0e3d1ccfc20de48fa6bf49e6c89MD5 of the rootkit object file ccTltpHf.o.
MD5305264d95d5056bc5de3a0b683bcd7ebMD5 of the cryptominer binary cpuMinerTermux.koske.
MD563e613cab023c023d74e9dc8e0168e54MD5 of the rootkit binary hideproc.so.
MD56e9929b127afc5b4351ba3318e2178dcMD5 of a ccminer binary.
MD576c5d978d6ef48af4350a12f238e48c4MD5 of the rootkit code file hideproc.c.
URLhxxp[:]//tiny[.]cc/panda-v14Image download URL listed as an indicator for the payload-delivery attack.
URLhxxps[:]//i[.]imgs[.]ovh/2025/07/17/DGlLc[.]jpegImage download URL listed as an indicator for the payload-delivery attack.
URLhxxps[:]//i[.]imgs[.]ovh/2025/07/17/DmvmA[.]jpegImage download URL listed as an indicator for the payload-delivery attack.
URLhxxps[:]//iili[.]io/FhFK3Eg[.]jpgImage download URL listed as an indicator for the payload-delivery attack.
URLhxxps[:]//k0ske[.]short[.]gy/panda_v14Image download URL listed as an indicator for the payload-delivery attack.

MITRE ATT&CK

Malware

Vendors

Products

Tools

Countries

Related Articles