Katana
Katana is referenced in Nokia Deepfield ERT public research as a DDoS botnet. The available content indicates that a report named "katana" exists in the deepfield/public-research repository and that the material contains DDoS botnet research and indicators of compromise. Additional mention context states that Katana is discussed alongside Satori and other emerging forks, with noted characteristics including large exploit libraries, faster propagation, evasive command-and-control, and self-updating modules. No specific threat actor attribution, infection vector details, targeted industries, victimology, attack timeline, platform details, or concrete indicators of compromise are provided in the available content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Reconnaissance
1 technique
Reconnaissance
Initial Access
1 technique
Initial Access
Persistence
1 technique
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Stealth
1 technique
Stealth
Credential Access
1 technique
Credential Access
Discovery
1 technique
Discovery
Lateral Movement
1 technique
Lateral Movement
Command and Control
4 techniques
Command and Control
"Self-updating modules, allowing attackers to rapidly push new exploits as they appear."
“Evasive command-and-control techniques, including domain-fluxing and encrypted command channels.”
IOCs tracked for this family
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modern Mirai fork/strain described as part of the new generation of IoT botnet variants, featuring expanded exploit capabilities, rapid propagation, evasive C2, and modular/self-updating behavior to support sustained DDoS operations.
Modern Mirai fork/variant described as incorporating large IoT exploit libraries, high-speed propagation, evasive C2 (including domain-fluxing/encrypted channels), and self-updating modules to maintain and expand DDoS botnet capability.
A modern Mirai fork/variant with expanded exploit coverage, rapid propagation, evasive/encrypted C2, and self-updating modules to maintain and scale IoT botnet-driven DDoS activity.
Katana is referenced as a named DDoS botnet in Nokia Deepfield ERT research.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.