TLDR: Aqua Security researchers have identified Koske, a sophisticated Linux cryptomining malware believed to be developed with significant AI assistance, possibly utilizing a large language model. Koske employs advanced evasion techniques, including polyglot image files disguised as panda images and rootkits, to conceal its malicious activities. Its adaptive behavior, such as multiple connectivity checks and dynamic proxy discovery, marks a significant leap in AI-generated malware capabilities.
Aqua Security’s research arm, Aqua Nautilus, has uncovered a groundbreaking Linux malware named ‘Koske,’ which signals an unsettling shift in the landscape of cyber threats. This sophisticated cryptomining malware exhibits clear signs of AI-assisted development, likely leveraging large language models (LLMs) to craft its modular payloads, evasive rootkits, and stealthy persistence mechanisms. According to Assaf Morag, director of security research at Aqua Security, ‘The line between human and machine-generated threats is starting to blur,’ emphasizing that Koske represents a ‘new breed of persistent and adaptable malware built for one purpose: cryptomining. It is a warning of what is to come.’
Koske’s operators initiate their attacks by exploiting misconfigured servers, subsequently installing backdoors and downloading what appear to be harmless JPEG images from shortened URLs. These images are, in fact, polyglot files, meaning they contain malicious payloads appended to their end. Once downloaded, the malware extracts and executes these malicious segments directly in memory, effectively bypassing traditional antivirus tools. The malware also incorporates ‘unusual’ evasion and persistence techniques, ‘boosted’ by AI, which allow it to exploit misconfigurations or vulnerabilities with enhanced efficiency.
Further analysis by Aqua Security indicates that AI has likely been instrumental in writing Koske’s code, evidenced by its ‘verbose, well-structured comments and modularity,’ as well as ‘best-practice logic flow with defensive scripting habits.’ This AI-generated code can also appear generic, complicating attribution and analysis for defenders. Koske is designed to mine various cryptocurrencies, including Monero, Ravencoin, Nexa, Tari, and Zano, and can deploy CPU- or GPU-optimized miners based on the compromised system’s capabilities. It also features adaptive behavior, automatically switching coins or mining pools if one fails.
Also Read:
- Veracode Report: Nearly Half of AI-Generated Code Contains Security Flaws
- Adversa AI’s 2025 Report: Generative and Agentic AI Under Escalating Cyberattack
This discovery highlights the dual-use nature of AI. While cybersecurity defenders are increasingly utilizing LLMs for threat detection, attackers are now leveraging AI to create more sophisticated, evasive, and adaptable malware. As CyberArk noted in a recent report, ‘Given the aptitude that generative AIs have for writing code, it’s no surprise that threat actors are using them to do exactly that.’ The emergence of Koske underscores the accelerating ‘arms race’ in cybersecurity, necessitating that organizations adopt behavioral and context-aware security solutions to defend modern Linux workloads against these evolving AI-enhanced threats.


