A newly discovered IoT malware family called KATARU is targeting Linux devices via Telnet credential brute-force attacks. Researchers discovered that it also includes a variety of Linux privilege-escalation exploits, persistence methods, encrypted command-and-control communications, anti-analysis checks, and decoy network traffic. If that fails, the malware tries several public Linux local privilege-escalation exploits, including code for CVE-2026-46300, known as Fragnesia; CVE-2026-43284, called DirtyFrag; and CVE-2026-31431, known as Copy Fail.
It targets systemd services and timers, cron jobs, SysV init scripts, rc.local, shell profile files, OpenWrt scripts, NetworkManager hooks, DHCP hooks, package-manager hooks, and Android boot-service locations. The C2 server can instruct infected devices to launch various attacks, including TCP, UDP, ICMP, HTTP, QUIC, DNS, and game-service floods.
Additionally, it supports SSH brute forcing, downloading and running additional payloads, executing shell commands, stopping attacks, or uninstalling malware. Nozomi Networks confirmed these capabilities. Indicators of Compromise Indicator Type Description IP Address 160.191.242.92 Observed Telnet credential brute-force source and KATARU C2 infrastructure SHA-256 cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218 Suspected loader or closely related dropper used to stage K












