Skip to content
KATARU IoT Malware Exploits Linux Vulnerabilities for DDoS Attacks

KATARU IoT Malware Exploits Linux Vulnerabilities for DDoS Attacks

First seen 11 Sep 2026, 16:17 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 21:57 UTC
  • KATARU malware exploits Linux vulnerabilities to escalate privileges and launch DDoS attacks.
  • The malware uses Telnet brute-forcing and includes multiple public exploits like CVE-2026-46300.
  • It features extensive persistence mechanisms, making it difficult to remove once deployed.

The KATARU malware targets internet-exposed IoT devices using Telnet credential brute-forcing. Once access is gained, it attempts to escalate privileges using public Linux exploits, including CVE-2026-46300, CVE-2026-43284, and CVE-2026-31431. The malware combines Mirai-style DDoS capabilities with encrypted command-and-control communications and extensive persistence mechanisms. It was first identified in August 2026 after a honeypot was compromised by an attacker from Vietnam. The malware's architecture indicates it may have been developed with AI assistance, as it includes misconfigured exploit code and lacks adequate testing for target architectures. KATARU's persistence methods are notably broad, affecting various Linux and embedded systems. The malware has been confirmed to contain x86-oriented shellcode despite being an ARM binary, suggesting a lack of proper adaptation by its authors. Security experts recommend immediate defensive measures against this evolving threat.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-04
First public PoC for CVE-2026-31431
CVE-2026-31431, a local root escalation vulnerability, had its first public proof-of-concept released.
Gbhackers
2026-05-08
CVE-2026-43284 published
CVE-2026-43284, affecting Linux kernel networking, was published and is a local root escalation risk.
Gbhackers
2026-05-23
CVE-2026-46300 published
CVE-2026-46300, which allows unprivileged users to gain root access, was published.
Gbhackers
2026-08-01
KATARU malware identified
The KATARU malware was identified after a honeypot was compromised through Telnet brute-forcing from an IP in Vietnam.
Nozomi Networks
2026-09-11
KATARU malware reported
Multiple cybersecurity outlets reported on the KATARU malware, detailing its capabilities and attack methods.
Gbhackers

More articles in this cluster (4)

Following this threat?

Track Katana and CVE-2026-31431 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed