logo

New Koske Linux malware hides in cute panda images

ID: 6a905b78-9811-5332-8ba8-02a8756fb496

STIX ID: report--6a905b78-9811-5332-8ba8-02a8756fb496

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-07-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Koske is a sophisticated Linux malware campaign that abuses exposed JupyterLab instances to fetch seemingly benign JPEG panda images which are actually polyglot files embedding a shell script and C code. The attack compiles and executes a rootkit in memory (using LD_PRELOAD) while running a memory-resident shell payload that establishes persistence (cron and systemd), evades detection, hardens network settings, and downloads CPU/GPU-optimized cryptominers supporting 18 coins; researchers note indicators (Serbian IPs/phrases, Slovak repo) and suspect AI-assisted development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.