Skip to content

New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks

Gbhackers Mayura Kathir September 11, 2026

A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root privileges with publicly available Linux kernel exploits before enrolling compromised systems in a DDoS botnet. The sample combines familiar Mirai-style flooding functions with encrypted command-and-control, broad persistence logic, anti-analysis checks and decoy network activity designed […]

Extracted Entities