Katana is referenced in Nokia Deepfield ERT public research as a DDoS botnet. The available content indicates that a report named "katana" exists in the deepfield/public-research repository and that the material contains DDoS botnet research and indicators of compromise. Additional mention context states that Katana is discussed alongside Satori and other emerging forks, with noted characteristics including large exploit libraries, faster propagation, evasive command-and-control, and self-updating modules. No specific threat actor attribution, infection vector details, targeted industries, victimology, attack timeline, platform details, or concrete indicators of compromise are provided in the available content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
"Self-updating modules, allowing attackers to rapidly push new exploits as they appear."
“Evasive command-and-control techniques, including domain-fluxing and encrypted command channels.”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modern Mirai fork/strain described as part of the new generation of IoT botnet variants, featuring expanded exploit capabilities, rapid propagation, evasive C2, and modular/self-updating behavior to support sustained DDoS operations.
Modern Mirai fork/variant described as incorporating large IoT exploit libraries, high-speed propagation, evasive C2 (including domain-fluxing/encrypted channels), and self-updating modules to maintain and expand DDoS botnet capability.
A modern Mirai fork/variant with expanded exploit coverage, rapid propagation, evasive/encrypted C2, and self-updating modules to maintain and scale IoT botnet-driven DDoS activity.
Katana is referenced as a named DDoS botnet in Nokia Deepfield ERT research.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.