Surely it can't be easy as downgrading the kernel then using towelroot. I'm guessing if you tried to flash the older kernel, it wouldn't let you, or it would trip knox.
To see knox counter: boot into download mode. 0x0 = good 0x1 = bad.
Are you saying that it's possible for the malware to not show up at all in the running applications list? Or do you mean that it's likely going to be disguised as a normal system process and hard to find?
From what I read, it only works on device, not the SD card. Keep that in mind when testing.
I would cite my sources, but I don't have 10 posts yet.
do a google inurl:"galaxy-note-3-usb-3-0-file-transfer-benchmark/"