← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 11, 2026 · 14:17via Cyber Security News

New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks

Brief

KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used repeated Telnet password guesses against a honeypot, then downloaded an ARM payload.

It shows how old entry points still give attackers a foothold. The malware resembles the Mirai botnet family in its ability to flood targets with traffic, but carries wider tools.

It can attempt to gain root access, stay active through reboots, hide command traffic, and run commands supplied by its operators. A compromised device can therefore be harder to remove and more useful in attacks.

Analysts at Nozomi Networks identified the sample in August and named the family KATARU after a ChaCha20 nonce used to decrypt its configuration.

Read more on Cyber Security News→