Executive Summary
In August 2026, researchers at Nozomi Networks identified KATARU, a new IoT malware strain targeting ARM and AMD64 architectures. The malware gains initial access through Telnet credential brute forcing, followed by the deployment of payloads that attempt to gain root access using public exploits for vulnerabilities including CVE-2026-46300 (Fragnesia), CVE-2026-43284 (DirtyFrag), and CVE-2026-31431 (Copy Fail).
KATARU stands out for its broad capability set, which appears to be assembled using public proof-of-concept code and potentially AI assistance. It features an encrypted custom Command and Control (C2) channel using X25519 key exchange and ChaCha20-Poly1305 encryption, departing from the plain-text traffic typical of older Mirai-style botnets. The malware includes extensive persistence mechanisms across Linux, Android, and various embedded systems, and utilizes decoy traffic layers to complicate automated analysis and IOC extraction.
While implementation artifacts—such as architecture-mismatched shellcode—suggest limited validation by the operators, the malware remains a significant threat to critical infrastructure and industrial environments. Its ability to achieve persistent root access on poorly secured IoT devices enables durable DDoS nodes capable of flooding services like Minecraft, OpenVPN, and WireGuard.
