Explaining the AI-Assisted Koske Linux Cryptomining Malware Hidden in JPEGs
ID: ed8988e8-edb1-5116-a676-eb3ef3f2ff96
STIX ID: report--ed8988e8-edb1-5116-a676-eb3ef3f2ff96
Feed Name: Resources-2
Date Published: 2025-08-29
Date Updated: 2026-07-22
Author: [email protected] (Sıla Özeren Hacıoğlu)
## Executive summary This report describes the Koske 2025 Linux cryptomining campaign — an AI-assisted, modular threat that delivers and executes hidden payloads (e.g., polyglot JPEGs), establishes persistence via kernel modules, RC scripts, systemd and cron, evades detection using LD_PRELOAD hooks and firewall tampering, and stages encrypted XMrig miners; the document also details Picus simulation steps that safely emulate these TTPs to validate detection and defensive coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
