$ techbeacon▋
CVE & Exploits

Emerging IoT Malware Exploits Linux Flaws to Build DDoS Botnet

Emerging IoT Malware Exploits Linux Flaws to Build DDoS Botnet

A newly identified family of Internet‑of‑Things malware, dubbed KATARU, is targeting network‑connected devices that expose Telnet services, researchers report. The code first attempts to log in using brute‑forced credentials, then leverages publicly disclosed Linux kernel vulnerabilities to obtain root access before enrolling the host in a distributed denial‑of‑service (DDoS) botnet.

The infection chain begins with wide‑area scans for devices listening on port 23. Once a candidate is found, the malware cycles through common default usernames and passwords, a technique popularized by earlier IoT threats such as Mirai. Successful authentication triggers the download of a payload that contains exploits for recent Linux kernel bugs that have been patched publicly but remain unaddressed on many embedded systems.

Linux‑based firmware powers a large segment of smart cameras, routers, and industrial controllers. Manufacturers often ship devices with outdated kernels to reduce cost and development time, and many owners never apply updates. Combined with the prevalence of weak or unchanged Telnet credentials, these factors create a fertile environment for automated compromise.

Security analysts note that KATARU’s use of kernel‑level exploits marks a step up from prior IoT malware that relied solely on credential reuse. By escalating privileges, the code can bypass user‑level restrictions, install persistent rootkits, and more reliably integrate the device into a command‑and‑control network. This escalation could broaden the pool of vulnerable hardware, including devices that employ strong passwords but run unpatched kernels.

Once a device is under control, KATARU connects it to a DDoS botnet that can be directed to flood target servers with traffic, potentially overwhelming web services, APIs, or critical infrastructure. While no large‑scale attacks have been publicly linked to the strain so far, the capability mirrors that of earlier botnets that generated multi‑gigabit attacks against high‑profile sites.

Researchers from the GBHackers community and other security firms recommend immediate mitigation steps: disable Telnet where possible, enforce unique strong passwords, and apply the latest firmware or kernel patches supplied by device manufacturers. Network segmentation and intrusion‑detection systems that flag anomalous outbound traffic can also reduce the risk of compromised devices being used in attacks. Ongoing monitoring will determine whether KATARU evolves further or spawns new variants that target additional services.

Source: GBHackers
Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related