Malware & Threats

Sophisticated Koske Linux Malware Developed With AI Aid

The Koske Linux malware shows how cybercriminals can use AI for payload development, persistence, and adaptivity.

Linux malware

Cybercriminals appear to have employed AI to a significant extent in the development of a sophisticated Linux malware named Koske, according to cloud and container security firm Aqua Security. 

Koske is designed to abuse compromised systems for cryptocurrency mining. It deploys CPU- and GPU-optimized miners — depending on the device’s capabilities — to leverage the host’s resources to mine for Monero, Ravecoin, Nexa, Tari, Zano and a dozen other cryptocurrencies.

In attacks observed by Aqua, the malware has been distributed on misconfigured instances of the JupyterLab web-based development environment.

On compromised systems, the attackers install backdoors and download two apparently harmless JPEG image files. 

These files are actually polyglots — when opened, they display an image of a panda, but they also embed malicious shellcode that fetches additional payloads, including a rootkit.

Aqua researchers believe Koske’s development has been significantly aided by AI. They believe the malware’s developers have used LLMs to create modular and evasive payloads, to design various persistence mechanisms that leave little trace, and ensure that the malware can automatically adapt to different system conditions. 

Advertisement. Scroll to continue reading.

In terms of adaptability, for instance, the malware uses three different methods to check if it has access to the GitHub account from which it fetches payloads. If it cannot connect, it resets proxy settings, removes iptables firewall rules on the operating system, and changes the DNS configuration. In addition, it can dynamically discover working proxies for C&C communications. 

Aqua has determined that AI has likely been used to write Koske’s code based on several clues, including “verbose, well-structured comments and modularity” and “best-practice logic flow with defensive scripting habits”.

Another noteworthy aspect is that code written by AI can look generic and make attribution and analysis more difficult.

“While using AI to generate better code already poses a challenge for defenders, it’s only the beginning. The real game-changer is AI-powered malware, which is malicious software that dynamically interacts with AI models to adapt its behavior in real-time. This kind of capability could mark a meteoric leap in adversaries’ tactics, putting countless systems at serious risk,” Aqua Security warned.

Related: New ‘Auto-Color’ Linux Malware Targets North America, Asia

Related: New ‘Hadooken’ Linux Malware Targets WebLogic Servers

Related: Linux Malware Campaign Targets Misconfigured Cloud Servers

Related Content

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Artificial Intelligence

Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5.

Artificial Intelligence

Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment.

Cybercrime

We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it.

Artificial Intelligence

Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network.

Artificial Intelligence

The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities. 

Artificial Intelligence

A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.

Artificial Intelligence

Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version