logo

Explaining the AI-Assisted Koske Linux Cryptomining Malware Hidden in JPEGs

ID: ed8988e8-edb1-5116-a676-eb3ef3f2ff96

STIX ID: report--ed8988e8-edb1-5116-a676-eb3ef3f2ff96

Feed Name: Resources-2

Threat Score
70/100

Date Published: 2025-08-29

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

## Executive summary This report describes the Koske 2025 Linux cryptomining campaign — an AI-assisted, modular threat that delivers and executes hidden payloads (e.g., polyglot JPEGs), establishes persistence via kernel modules, RC scripts, systemd and cron, evades detection using LD_PRELOAD hooks and firewall tampering, and stages encrypted XMrig miners; the document also details Picus simulation steps that safely emulate these TTPs to validate detection and defensive coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.