KATARU is a Mirai-like IoT botnet malware family targeting poorly secured Linux-based embedded devices. It has been observed obtaining access through Telnet credential brute forcing, after which an ARM payload is retrieved and executed using BusyBox utilities. The malware supports command-and-control-directed DDoS floods using TCP, UDP, ICMP, HTTP, QUIC, DNS, and application-specific routines targeting services such as Minecraft, FiveM, OpenVPN, and WireGuard.
KATARU uses encrypted command-and-control based on X25519 key exchange and ChaCha20-Poly1305. Operators can task infected devices to execute shell commands, download and run additional binaries, conduct SSH credential brute forcing, stop active floods, and remove malware components. It attempts local privilege escalation by modifying writable password data, invoking public Linux local privilege-escalation exploit code associated with CVE-2026-46300, CVE-2026-43284, and CVE-2026-31431, and attempting a cgroup v1 release-agent escape. Some embedded privilege-escalation code is architecture mismatched in analyzed ARM builds, limiting confidence in its operational effectiveness.
The family implements broad persistence logic across Linux and embedded environments, including systemd, cron, init scripts, OpenWrt mechanisms, package-management hooks, and boot-related locations. It also includes Android-oriented boot persistence attempts. When permissions permit, it may attempt to make copied components immutable or append-only. Anti-analysis and defense-evasion features include debugger and tracing checks, environment and process checks, timing checks, encrypted C2, self-removal, and decoy web-like, IRC-like, TCP, and UDP traffic. No named threat actor attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
KATARU attempts public code for CVE-2026-46300, Fragnesia; CVE-2026-43284, DirtyFrag; and CVE-2026-31431, Copy Fail. | KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes... KATARU begins with Telnet credential brute forcing, then uses BusyBox commands to retrieve and execute a payload.
KATARU attempts public code for CVE-2026-46300, Fragnesia; CVE-2026-43284, DirtyFrag; and CVE-2026-31431, Copy Fail. | KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes... KATARU begins with Telnet credential brute forcing, then uses BusyBox commands to retrieve and execute a payload.
KATARU attempts public code for CVE-2026-46300, Fragnesia; CVE-2026-43284, DirtyFrag; and CVE-2026-31431, Copy Fail. | KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes... KATARU begins with Telnet credential brute forcing, then uses BusyBox commands to retrieve and execute a payload.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
“Once running, it checks whether /etc/passwd is writable and tries to remove the root password placeholder.”
“It then attempts public code for CVE-2026-46300 ... CVE-2026-43284 ... and CVE-2026-31431 ... [and] a cgroup v1 release_agent escape that can relaunch the malware with higher privileges.”
“Once running, it checks whether /etc/passwd is writable and tries to remove the root password placeholder.”
Copie dans plusieurs emplacements ; utilisation de CAP_LINUX_IMMUTABLE pour rendre les copies immuables.
T1016 – System Network Configuration Discovery: Reads /proc/net/*, resolv.conf, and the local IP.
Fonctionnalités : botnet style Mirai, communications C2 chiffrées, anti-analyse, trafic leurre.
T1095 – Non-Application Layer Protocol: Custom length-prefixed binary protocol over TCP (port 6767).
“KATARU begins with Telnet credential brute forcing, then uses BusyBox commands to retrieve and execute a payload.” It can also “download additional binaries through wget.”
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
KATARU is an IoT-focused DDoS botnet malware family. It brute-forces Telnet credentials, uses BusyBox to download and execute payloads, attempts to obtain root privileges, and establishes persistence through multiple Linux, router, OpenWrt, Android, cron, systemd, and package-management mechanisms. It encrypts C2 using X25519 and ChaCha20-Poly1305, supports multiple flood types (TCP, UDP, ICMP, HTTP, QUIC, and DNS), can brute-force SSH on operator command, download additional binaries, execute shell commands, and remove its files.
An IoT-focused DDoS botnet that brute-forces Telnet credentials to compromise poorly secured devices and downloads an ARM payload. It attempts privilege escalation and extensive cross-platform persistence; uses encrypted X25519 and ChaCha20-Poly1305 C2; supports TCP, UDP, ICMP, HTTP, QUIC, and DNS flooding; and can brute-force SSH, download binaries, execute commands, halt attacks, and remove itself.
Malware IoT de type botnet, livré sur des systèmes compromis via Telnet après devinette d’identifiants. Il établit des communications C2 chiffrées, emploie des techniques d’anti-analyse et de leurre, tente une escalade de privilèges par modification de /etc/passwd, exploits LPE publics et échappement cgroup v1, puis établit une persistance via systemd, cron et des chemins Linux/IoT.
Linux/embedded IoT botnet that gains access through Telnet credential brute forcing, attempts local privilege escalation, establishes broad persistence, uses an encrypted custom C2 protocol, executes C2 commands and downloaded payloads, performs SSH brute forcing, and conducts multiple DDoS flood attacks. It also contains anti-analysis and deliberately misleading decoy network traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.