Koske is a Linux-focused cryptomining malware strain active in 2025 and described as targeting cloud services and hacked Jupyter Notebook environments. Reporting states it is used for hidden cryptocurrency mining and is notable for signs of AI- or LLM-assisted development, including well-structured code, modular design, defensive scripting habits, and AI-generated code blocks. The malware has been described as using an image-based delivery mechanism in which miner payloads are hidden inside JPEG images, and as being deployed on compromised Jupyter Notebooks. High-confidence reporting also attributes to Koske multiple persistence mechanisms on Linux, including installation of a rootkit, scheduled cron jobs, and modification of Linux startup files. Additional reported behavior includes resilient connectivity logic such as proxy discovery and failover, changing DNS or proxy settings, and erasing firewall rules to maintain command-and-control or mining connectivity. Koske is consistently characterized as a Linux cryptominer rather than a general-purpose backdoor, and has been referenced alongside other cloud-targeting cryptomining campaigns such as Soco404.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cloud-focused malware campaign deploying cryptominers by exploiting vulnerabilities/misconfigurations (per summary).
AI-generated cryptominer mentioned as a prior example; described as having other miners it could be modeled on.
Koske is an advanced, AI-assisted Linux cryptomining malware campaign. It uses polyglot JPEG files to hide shell payloads, achieves persistence through kernel modules, RC scripts, systemd services, and cron jobs, and evades detection via LD_PRELOAD hijacking and firewall tampering. Its primary goal is to hijack CPU and GPU resources for cryptomining, deploying encrypted XMrig miners on compromised systems.
AI-generated Linux cryptominer with layered persistence and evasion: installs rootkit capabilities to hide artifacts, persists via cron and startup file modifications (e.g., .bashrc/.bash_logout) and systemd services, and includes resilient C2/connectivity logic (proxy/DNS manipulation, firewall rule tampering, failover).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.