HomeSecurityLinux malware Koske hides in images of Panda bears

Linux malware Koske hides in images of panda bears

A new, highly sophisticated Linux malware, called Koske, has come under the microscope of cybersecurity researchers, as it combines advanced obfuscation techniques (within seemingly innocent images of panda bears) and exploitation of misconfigurations in JupyterLab instances, while it is allegedly created with artificial intelligence.

Linux malware Koske Panda

The AquaSec research team that discovered the threat describes Koske as “ one of the most technically sophisticated threats seen on Linux in a while ,” noting its automation, adaptability, and technical polymorphism .

Detected in innocent panda

Koske's attack begins in an almost poetic way: via JPEG images of panda bears, hosted on popular services such as OVH, freeimage, and postimage. Although they appear as ordinary images, they are actually polyglot files — that is, files that can be interpreted as both an image and an executable script, depending on how they are opened.

See also: APT36 attacks BOSS Linux systems via ZIP files

The images have a normal JPEG header, but contain malicious shell script and C code, allowing for direct execution of commands and taking control of the system without any visible element that would arouse suspicion in the user.

JupyterLab exploit for initial access

Koske exploits neglected or misconfigured installations of JupyterLab, a popular data analysis tool, to gain initial access to targets. From there, it downloads payload images and executes malicious code directly in memory, completely bypassing disk storage — a tactic that makes it significantly more difficult to detect by antivirus and EDR solutions.

Malicious rootkit in memory and mining 18 cryptocurrencies

The attacks discovered by AquaSec hide a payload in each image, (both are installed in parallel).

The first payload is a C-based rootkit. It is written directly into memory, compiled, and executed as a shared object .so file.

See also: CISA added Linux kernel vulnerability to KEV List

The second payload is a shell script that enables system persistence via cron jobs and systemd services. It also implements network hardening and bypasses proxies by replacing /etc/resolv.conf to use Cloudflare and Google DNS, locking it using the chattr +i command, flushing iptables, resetting proxy variables, and using a custom module to brute-force working proxies via curl, wget, and raw TCP checks.

The final stage involves installing specialized cryptominers for over 18 different coins, including Monero (XMR), Ravencoin, Nexa, Zano, and Tari.

The Koske malware automatically chooses which miner to use, depending on the target's CPU and GPU performance , and if a mining pool is down, it switches to backup alternatives – a feature that suggests a high level of programmed intelligence and autonomy .

Linux malware Koske hides in images of panda bears

It may have been created with artificial intelligence

Perhaps the most worrying feature of Koske is its adaptability to changing environments. According to AquaSec, this behavior suggests that the malware was likely created with the help of large language models (LLMs) or automation tools, thus opening up the debate about the role of artificial intelligence in the mass production of sophisticated malicious code.

See also: New Chaos RAT variants attack Windows and Linux systems

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The use of LLMs to rapidly create, modify, or optimize malicious scripts is already one of the most concerning areas in cybersecurity, and Koske may be one of the first examples of “AI-assisted malware” on a large scale.

Unclear geographical traces, suspicious connections to Serbia and Slovakia

While AquaSec has not yet concluded on a secure performance, it notes the presence of Serbian IP addresses , Serbian phrases in the code, and the use of Slovak language in GitHub repositories associated with the miners. These indications leave open the possibility that the activity is linked to Eastern European cybercrime networks .

A "smart" malware that ushers in a new era of threats

Koske is not just another Linux malware. It is a groundbreaking cyberattack model, incorporating memory techniques, polymorphism, automation, and possibly artificial intelligence — sending a clear message that conventional approaches to defense are no longer sufficient.

The need for behavioral-level detection, specialized EDRs for Linux , and collaboration between security organizations is more urgent than ever.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS