Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Font size: +
3 minutes reading time (694 words)

Cybersecurity Threat Advisory: KATARU Malware Is Turning Exposed IoT Devices into Long-Term DDoS Bots

Threat update

A newly documented malware family named KATARU is hijacking internet-facing Linux devices, including routers and other IoT equipment, by guessing weak or default Telnet passwords. Once inside, it takes root-level control, embeds itself so it survives reboots, and enlists the device in a Mirai-style botnet used for large-scale DDoS attacks. Any organization with connected devices that are exposed to the internet, unpatched, or protected by default credentials should review its exposure now.

Technical Detail and Additional Info

What is the threat?

KATARU is a Linux and IoT malware strain first identified by Nozomi Networks Labs in August 2026, after a decoy system the researchers were operating was compromised through Telnet password guessing. It targets ARM and x86-64 devices and keeps the familiar functionality of Mirai-style botnets while adding more modern techniques.

The attack chain works as follows:

  • Initial access: Brute-forcing of exposed Telnet services that use weak or default credentials.
  • Privilege escalation: The malware attempts several publicly known Linux local privilege escalation methods to gain root, including CVE-2026-46300 (Fragnesia), CVE-2026-43284 (DirtyFrag), CVE-2026-31431 (Copy Fail), a writable /etc/passwd abuse, and a cgroup v1 release_agent escape.
  • Persistence: Broad persistence coverage across startup mechanisms such as systemd, cron, rc.local, and init scripts, so the malware returns after a reboot.
  • Command and control: Communications with the operator are encrypted (X25519 key exchange with ChaCha20-Poly1305), which limits visibility for basic network monitoring.
  • Actions on the device: DDoS attacks (including TCP, UDP, ICMP, HTTP, QUIC, and DNS floods, plus attacks aimed at game servers and VPN services), SSH brute-forcing of other systems, remote command execution, and download of additional malware.

The build Nozomi analyzed does not spread on its own. Brute-force activity is tasked by the attacker. The advisory does not identify specific affected device models or publish indicators of compromise.

Why is it noteworthy?

The entry point is decades old, but the payload is not. Rather than a short-lived botnet that is easy to burn down, KATARU is built for long-term control of a device. It combines encrypted command and control, multiple privilege escalation options, and deep persistence, and it relies on public tools and exploits, which makes it inexpensive for attackers to reuse and scale. The analyzed sample also contained exploit code written for a different processor architecture than the device it ran on, which suggests the operators are still iterating on it. 

What is the exposure or risk?

Organizations with internet-facing Linux-based devices that run Telnet, use weak or default passwords, or lack current firmware and kernel patches face the highest risk. That includes routers, cameras, building systems, and other connected equipment that often falls outside normal patching and monitoring.

A compromised device can be used to attack third parties, brute-force other systems, or receive additional malware. Even when a business is not the intended DDoS target, it can face saturated bandwidth, an IP address flagged as malicious, and an attacker-controlled foothold inside its network. Because the malware persists across reboots, restarting the device does not remove it. 

What are the recommendations?

 LBT Technology Group recommends the following actions:

  • Disable Telnet. Where remote management is required, use SSH restricted to a VPN or trusted network, never directly exposed to the internet.
  • Replace default and weak credentials. Use strong, unique passwords on every device.
  • Apply firmware and Linux kernel updates. KATARU's privilege escalation relies on known flaws that current updates address.
  • Segment IoT and OT devices. Keep them off direct internet exposure and away from business-critical systems.
  • Monitor for signs of compromise. Watch for unfamiliar outbound encrypted connections, sudden traffic spikes, unexpected Telnet or SSH attempts, and unauthorized changes to device startup configuration.
  • Rebuild compromised devices. Disconnect the device, factory reset it, and reconfigure it from scratch rather than simply rebooting.
  • Retire unsupported hardware. Replace devices that can no longer receive security updates.

References

 For more in-depth information about the recommendations, please visit the following links:

Business Continuity and Disaster Recovery: Could Y...

Related Posts

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024