TTO-2026-0913-124 · September 13, 2026 MalwareIoT

KATARU IoT Malware Exploits Three Linux Privilege Escalation CVEs and Deploys Mirai-Style DDoS Capability

Nozomi Networks researchFragnesia / DirtyFrag / CopyFail CVEsTelnet brute-force initial accessLinux privilege escalationMirai-style DDoSNo named vendor victim

Summary

Nozomi Networks has published research on KATARU, a previously undocumented IoT malware family captured in honeypot infrastructure in August and September 2026. KATARU gains initial access via Telnet brute-force against default and weak credentials on internet-exposed IoT devices, then chains three Linux privilege escalation vulnerabilities — internally designated Fragnesia, DirtyFrag, and CopyFail — to achieve root. Once rooted, KATARU deploys a Mirai-derived DDoS module capable of UDP flood, TCP SYN flood, and HTTP flood attack patterns, and establishes a persistent command-and-control channel. Targeted device categories include consumer routers, IP cameras, NAS devices, and industrial edge gateways.

Timeline

DateEvent
August 2026First KATARU samples captured in Nozomi Networks IoT honeypot infrastructure
Sep 1-10, 2026Additional honeypot captures confirm KATARU as an active campaign; three privilege escalation CVEs identified
Sep 13, 2026Nozomi Networks publishes full malware analysis including indicators of compromise and CVE details

What Happened

KATARU’s infection chain begins with automated Telnet scanning across IPv4 ranges, attempting login with a dictionary of approximately 800 default credential pairs common to consumer and industrial IoT devices. On successful authentication, KATARU drops a first-stage shell script that determines the device’s Linux kernel version and architecture, then selects the appropriate privilege escalation exploit from three candidates.

Fragnesia exploits a fragmentation handling flaw in the Linux network stack present in kernels shipped with many IoT devices through 2024. DirtyFrag is a variant of the DirtyPipe family targeting kernel versions 5.8 through 5.16 still running on a large population of unpatched routers and cameras. CopyFail exploits a copy-on-write race condition in kernels below 6.1 that is particularly reliable against ARM-based devices. At least one of the three is applicable to the majority of vulnerable IoT device firmware currently deployed.

After rooting the device, KATARU writes a persistent init script, connects to command-and-control infrastructure via a custom binary protocol on port 7531, and registers the device in a botnet pool. The DDoS module is loaded on command rather than immediately, suggesting KATARU’s operators are building botnet capacity for future attacks rather than conducting active DDoS campaigns at time of publication. Nozomi Networks has published a full list of indicators of compromise including C2 IP addresses, file hashes, and Telnet credential pairs. Organizations with internet-exposed IoT infrastructure should audit devices for Telnet exposure, enforce credential hardening, and apply available firmware updates.

Note on Domain Intelligence

KATARU is a malware family targeting internet-exposed IoT devices across multiple vendors. No single vendor or victim domain is named in this bulletin. Domain intelligence for specific affected device vendors is available at warmbadge.com where those domains have been evaluated.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 13, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026