Summary
Nozomi Networks has published research on KATARU, a previously undocumented IoT malware family captured in honeypot infrastructure in August and September 2026. KATARU gains initial access via Telnet brute-force against default and weak credentials on internet-exposed IoT devices, then chains three Linux privilege escalation vulnerabilities — internally designated Fragnesia, DirtyFrag, and CopyFail — to achieve root. Once rooted, KATARU deploys a Mirai-derived DDoS module capable of UDP flood, TCP SYN flood, and HTTP flood attack patterns, and establishes a persistent command-and-control channel. Targeted device categories include consumer routers, IP cameras, NAS devices, and industrial edge gateways.
Timeline
| Date | Event |
|---|---|
| August 2026 | First KATARU samples captured in Nozomi Networks IoT honeypot infrastructure |
| Sep 1-10, 2026 | Additional honeypot captures confirm KATARU as an active campaign; three privilege escalation CVEs identified |
| Sep 13, 2026 | Nozomi Networks publishes full malware analysis including indicators of compromise and CVE details |
What Happened
KATARU’s infection chain begins with automated Telnet scanning across IPv4 ranges, attempting login with a dictionary of approximately 800 default credential pairs common to consumer and industrial IoT devices. On successful authentication, KATARU drops a first-stage shell script that determines the device’s Linux kernel version and architecture, then selects the appropriate privilege escalation exploit from three candidates.
Fragnesia exploits a fragmentation handling flaw in the Linux network stack present in kernels shipped with many IoT devices through 2024. DirtyFrag is a variant of the DirtyPipe family targeting kernel versions 5.8 through 5.16 still running on a large population of unpatched routers and cameras. CopyFail exploits a copy-on-write race condition in kernels below 6.1 that is particularly reliable against ARM-based devices. At least one of the three is applicable to the majority of vulnerable IoT device firmware currently deployed.
After rooting the device, KATARU writes a persistent init script, connects to command-and-control infrastructure via a custom binary protocol on port 7531, and registers the device in a botnet pool. The DDoS module is loaded on command rather than immediately, suggesting KATARU’s operators are building botnet capacity for future attacks rather than conducting active DDoS campaigns at time of publication. Nozomi Networks has published a full list of indicators of compromise including C2 IP addresses, file hashes, and Telnet credential pairs. Organizations with internet-exposed IoT infrastructure should audit devices for Telnet exposure, enforce credential hardening, and apply available firmware updates.
Note on Domain Intelligence
KATARU is a malware family targeting internet-exposed IoT devices across multiple vendors. No single vendor or victim domain is named in this bulletin. Domain intelligence for specific affected device vendors is available at warmbadge.com where those domains have been evaluated.
The Trust Observatory · thetrustobservatory.com · September 13, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026