Back to Intelligence

KATARU IoT Botnet + Mirai-Style Telnet Brute-Force: OTX Pulse Analysis — Linux LPE Exploit & Detection Pack

SA
Security Arsenal Team
October 11, 2026
9 min read

A new OTX pulse from AlienVault, based on Nozomi Networks research, documents the emergence of KATARU, an IoT malware variant first observed in August 2026 after it brute-forced Telnet credentials against a Vietnam-based honeypot. KATARU preserves the classic Mirai botnet playbook — credential stuffing over Telnet, mass scanning, and DDoS capability — but layers on a materially more dangerous feature set that shifts it from commodity IoT nuisance to enterprise-relevant intrusion vector.

The attack chain is straightforward but effective: (1) Internet-wide scanning for exposed Telnet services, (2) brute-force authentication using embedded and default credential dictionaries, (3) payload staging onto the compromised Linux/embedded host, (4) local privilege escalation using one of three public exploits — CVE-2026-31431, CVE-2026-43284, and CVE-2026-46300, (5) multi-layered persistence across both standard Linux and embedded platforms, and (6) encrypted command-and-control for botnet tasking including DDoS operations.

The operator's objective appears to be botnet scale and resilience. The integration of multiple LPE exploits is the key differentiator: it allows KATARU to convert low-privileged Telnet access (often a restricted shell on an IoT device) into root, enabling deeper persistence, credential harvesting from memory and on-disk stores, and defense evasion. For enterprises, the credential-theft dimension is the sleeper risk — compromised Linux hosts on the same segment as IoT/OT infrastructure become pivot points, and harvested credentials from those systems feed the broader dark web credential economy.

Threat Actor / Malware Profile

Malware families: KATARU (primary), Mirai lineage (codebase heritage) Attribution: Unknown operator; no public attribution at time of this briefing.

Distribution method: Telnet brute-force against Internet-exposed devices (TCP/23). The initial observation came via a honeypot in Vietnam, consistent with Mirai-family scanning patterns that sweep for exposed embedded devices, routers, DVRs, IP cameras, and poorly segmented Linux servers.

Payload behavior:

  • DDoS tasking inherited from Mirai-style botnet architecture (UDP/TCP floods)
  • Local privilege escalation via three packaged public exploits (CVE-2026-31431, CVE-2026-43284, CVE-2026-46300), executed opportunistically depending on kernel/distro fingerprint
  • Credential access: scraping of /etc/passwd, /etc/shadow, shell history, and accessible credential stores post-escalation
  • Lateral scanning propagation to continue Telnet brute-force from newly infected hosts

C2 communication: Encrypted C2 channel — a departure from the plaintext or trivially XOR-encoded C2 typical of legacy Mirai variants. Encryption frustrates network-based signature detection and passive protocol fingerprinting; detection must therefore lean on behavioral analytics (beaconing periodicity, destination rarity, JA3/JA4 fingerprinting) rather than payload inspection.

Persistence mechanism: Comprehensive persistence across Linux and embedded platforms — expect a combination of cron entries, modified init scripts / rc.local, systemd service units, and SSH authorized_keys implantation on full Linux systems, plus init/rcS modification on embedded firmware where writable.

Anti-analysis techniques: Encrypted C2 (defeats string-based and DPI analysis), likely process name masquerading as legitimate system daemons, and exploit-based rootkit-adjacent behavior following LPE (log tampering of wtmp/utmp/auth.log is common in this class).

IOC Analysis

This pulse contains 16 indicators across two types:

  • CVE identifiers (3): CVE-2026-31431, CVE-2026-43284, CVE-2026-46300 — these are not blockable indicators; they are attack surface indicators. Feed them into your vulnerability management platform (Qualys, Tenable, Rapid7) immediately and cross-reference against all Linux and embedded assets. Any unpatched, Telnet-exposed host matching these CVEs is a pre-compromised asset in waiting.
  • FileHash-SHA256 (5 shown of 16 total): KATARU payload binaries, likely multi-architecture builds (Mirai-family malware compiles for x86, ARM, MIPS, etc.). Operationalize by pushing the full hash set into your EDR blocklist, threat intelligence platform (MISP, ThreatConnect), and SIEM watchlists. Note that hash-based detection has a short half-life for actively developed malware — pair hash blocking with the behavioral detections below.

SOC operationalization guidance: Ingest the pulse via the OTX API or TAXII feed into your TIP with the kataru tag. For hash lookups at scale, use grep against EDR telemetry exports, Velociraptor's hash() hunting artifacts, or Sentinel's ThreatIntelligenceIndicator table join (see KQL below). For CVE exposure, correlate vulnerability scan results with network flow data showing inbound TCP/23.

Detection Engineering

YAML
---
title: KATARU IoT Malware - Telnet Brute-Force Followed by Shell Execution
id: 8f3a1c2e-9b4d-4e6a-a1f2-kataru000001
status: experimental
description: Detects high-frequency failed Telnet authentication followed by successful login and immediate shell/binary execution, consistent with KATARU/Mirai-family brute-force infection chains.
author: Security Arsenal Threat Intelligence
date: 2026/10/11
logsource:
  product: linux
  service: auth
detection:
  selection_failed:
    - 'Failed password'
    - 'authentication failure'
  selection_telnet:
    - 'telnet'
    - 'in.telnetd'
    - 'port 23'
  timeframe: 10m
  condition: selection_failed and selection_telnet
  count: selection_failed >= 10
level: high
tags:
  - attack.credential_access
  - attack.t1110
  - attack.brute_force
  - kataru
  - mirai
---
title: KATARU - Linux Local Privilege Escalation Exploit Execution
id: 8f3a1c2e-9b4d-4e6a-a1f2-kataru000002
status: experimental
description: Detects non-root processes spawning setuid-root shells or writing to privileged paths, consistent with post-exploitation behavior after KATARU's public LPE exploits (CVE-2026-31431, CVE-2026-43284, CVE-2026-46300).
author: Security Arsenal Threat Intelligence
date: 2026/10/11
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent_lowpriv:
    ParentUser|contains:
      - 'www-data'
      - 'nobody'
      - 'daemon'
      - 'admin'
      - 'root:!'
  selection_child:
    Image|endswith:
      - '/bash'
      - '/sh'
      - '/dash'
  selection_uid_change:
    EffectiveUser: 'root'
  condition: selection_parent_lowpriv and selection_child and selection_uid_change
falsepositives:
  - Legitimate su/sudo administrative activity (filter via audit trails)
level: critical
tags:
  - attack.privilege_escalation
  - attack.t1068
  - kataru
---
title: KATARU - Persistence via Cron, RC Scripts, or SSH Key Implant
id: 8f3a1c2e-9b4d-4e6a-a1f2-kataru000003
status: experimental
description: Detects file modifications to Linux persistence locations commonly abused by KATARU and Mirai-family malware for survival across reboots.
author: Security Arsenal Threat Intelligence
date: 2026/10/11
logsource:
  category: file_event
  product: linux
detection:
  selection_paths:
    TargetFilename|contains:
      - '/etc/cron'
      - '/var/spool/cron'
      - '/etc/rc.local'
      - '/etc/init.d/'
      - '/etc/rc.d/'
      - '/.ssh/authorized_keys'
      - '/etc/systemd/system/'
  selection_writers:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/wget'
      - '/curl'
      - '/busybox'
  condition: selection_paths and selection_writers
level: high
tags:
  - attack.persistence
  - attack.t1053.003
  - attack.t1543
  - attack.t1098.004
  - kataru
KQL — Microsoft Sentinel / Defender
// KATARU IoT Botnet Hunt - Hash match + Telnet brute-force + encrypted beaconing
// Microsoft Sentinel / Defender XDR
let KataruHashes = dynamic([
  "9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5",
  "cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218",
  "13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4",
  "6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f",
  "9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc"
]);
let HashHits = DeviceFileEvents
  | where TimeGenerated > ago(14d)
  | where SHA256 in (KataruHashes)
  | project HitType="Known KATARU Binary", TimeGenerated, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessCommandLine;
let TelnetBruteForce = DeviceNetworkEvents
  | where TimeGenerated > ago(14d)
  | where RemotePort == 23 or LocalPort == 23
  | summarize ConnectionCount=count(), UniqueSources=dcount(RemoteIP) by DeviceName, RemoteIP, bin(TimeGenerated, 1h)
  | where ConnectionCount > 20
  | project HitType="Telnet Brute-Force Pattern", TimeGenerated, DeviceName, RemoteIP, ConnectionCount;
let Beaconing = DeviceNetworkEvents
  | where TimeGenerated > ago(7d)
  | where InitiatingProcessFileName !in~ ("chrome.exe","firefox.exe","svchost.exe","systemd","sshd")
  | summarize ConnCount=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated)
      by DeviceName, InitiatingProcessFileName, RemoteIP, RemotePort
  | where ConnCount > 50
  | extend IntervalMinutes = datetime_diff("minute", LastSeen, FirstSeen) / ConnCount
  | where IntervalMinutes between (1 .. 60)
  | project HitType="Suspected Encrypted C2 Beaconing", FirstSeen, DeviceName, InitiatingProcessFileName, RemoteIP, RemotePort, ConnCount;
union HashHits, TelnetBruteForce, Beaconing
| sort by TimeGenerated desc
Bash / Shell
#!/bin/bash
# KATARU IoT Botnet - Linux Host IOC & Persistence Hunt
# Run as root on suspected Linux/embedded hosts. Outputs to /tmp/kataru_hunt_$(hostname).log

LOG="/tmp/kataru_hunt_$(hostname).log"
echo "=== KATARU Hunt - $(date -u) ===" | tee "$LOG"

KATARU_HASHES=(
"9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5"
"cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218"
"13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4"
"6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f"
"9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc"
)

echo -e "\n[1] Hash sweep of common staging dirs (/tmp /var/tmp /dev/shm /usr/bin /usr/sbin)..." | tee -a "$LOG"
for dir in /tmp /var/tmp /dev/shm /usr/bin /usr/sbin; do
  [ -d "$dir" ] || continue
  find "$dir" -type f -maxdepth 2 2>/dev/null | while read -r f; do
    h=$(sha256sum "$f" 2>/dev/null | awk '{print $1}')
    for kh in "${KATARU_HASHES[@]}"; do
      if [ "$h" == "$kh" ]; then echo "  [!!] KATARU HASH MATCH: $f" | tee -a "$LOG"; fi
    done
  done
done

echo -e "\n[2] Recently modified persistence locations..." | tee -a "$LOG"
find /etc/cron* /var/spool/cron /etc/rc.local /etc/init.d /etc/rc.d /etc/systemd/system -type f -mtime -14 2>/dev/null | tee -a "$LOG"
echo "  --- SSH authorized_keys modified in last 14 days ---" | tee -a "$LOG"
find /root /home / -maxdepth 3 -name authorized_keys -mtime -14 2>/dev/null | tee -a "$LOG"

echo -e "\n[3] Suspicious cron content (wget/curl/busybox downloaders)..." | tee -a "$LOG"
grep -rEs "(wget|curl|busybox).*(http|ftp|tftp)" /etc/cron* /var/spool/cron 2>/dev/null | tee -a "$LOG"

echo -e "\n[4] Listening Telnet services (attack surface check)..." | tee -a "$LOG"
ss -tlnp 2>/dev/null | grep ':23 ' | tee -a "$LOG"

echo -e "\n[5] Outbound connections to rare IPs (potential encrypted C2)..." | tee -a "$LOG"
ss -tnp state established 2>/dev/null | grep -vE ':(22|80|443|53)\s' | tee -a "$LOG"

echo -e "\n[6] Processes running from deleted or tmp-backed binaries..." | tee -a "$LOG"
for pid in $(ls /proc | grep -E '^[0-9]+$'); do
  exe=$(readlink "/proc/$pid/exe" 2>/dev/null)
  case "$exe" in
    *deleted*|/tmp*|/dev/shm*|/var/tmp*) echo "  [!!] PID $pid -> $exe (cmdline: $(tr '\0' ' ' < /proc/$pid/cmdline 2>/dev/null))" | tee -a "$LOG";;
  esac
done

echo -e "\n[7] Auth log: Telnet brute-force evidence (top failed sources)..." | tee -a "$LOG"
grep -h "Failed password" /var/log/auth.log /var/log/secure 2>/dev/null | grep -oE 'from [0-9.]+' | sort | uniq -c | sort -rn | head -10 | tee -a "$LOG"

echo -e "\n=== Hunt complete. Review $LOG ===" | tee -a "$LOG"

Response Priorities

Immediate (0-4 hours):

  • Push all five SHA256 indicators to EDR blocklists and network sandbox detonation queues; import the full 16-IOC set from the OTX pulse into your TIP.
  • Block inbound TCP/23 (Telnet) at the perimeter and internal segmentation boundaries — there is almost no legitimate reason for Internet-facing Telnet in 2026.
  • Execute the Bash hunt script on Internet-adjacent Linux hosts and any system with network reachability to IoT/OT VLANs; run the KQL query across the last 14 days of telemetry.

24 Hours:

  • Treat this as credential theft exposure: any Linux host showing KATARU indicators had root-level access achieved — rotate all credentials present on that host (local accounts, SSH keys, service accounts, any cached domain/cloud tokens).
  • Audit SSH authorized_keys and /etc/shadow for unauthorized additions; review authentication logs for credential replay from harvested material.
  • Force password resets for any IoT device management credentials that used defaults, and verify MFA on any jump-host or management-plane accounts reachable from potentially compromised segments.

1 Week:

  • Remediate or isolate assets vulnerable to CVE-2026-31431, CVE-2026-43284, and CVE-2026-46300; where patching embedded devices is impossible, place them behind deny-by-default ACLs.
  • Architecturally segment IoT/OT networks from corporate IT with unidirectional monitoring where feasible; deploy honeypots (Cowrie/OpenCanary) on IoT segments as early-warning tripwires.
  • Deploy encrypted-C2 beaconing detection (JA4 fingerprinting, connection periodicity analytics) since payload-based network signatures will not catch KATARU's C2.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.