KATARU is a newly identified IoT malware family that targets internet-facing Linux devices and recruits them into Mirai-style DDoS botnets. It commonly gains access through exposed Telnet services protected by weak or default credentials.
What is the threat?
KATARU is an IoT and Linux malware strain that targets devices with exposed Telnet services and weak or default credentials. After gaining access, it downloads and executes a malicious payload and attempts to gain root privileges through known Linux exploits.
Once established, KATARU installs persistence mechanisms that allow it to survive reboots and maintain long-term access. It uses encrypted command-and-control communications to evade detection and can launch DDoS attacks, perform SSH brute-force activity, execute remote commands, and download additional malware.
Why is it noteworthy?
KATARU combines long-standing security weaknesses, including exposed Telnet services, weak passwords, and unpatched Linux systems, with modern malware capabilities such as encrypted C2 communications and persistent root-level access. Unlike many short-lived IoT botnets, KATARU is designed to maintain long-term control of compromised devices. The malware demonstrates how threat actors can combine publicly available tools and exploits to create effective and scalable attacks.
For organizations with IoT or OT environments, KATARU reinforces the importance of patching, hardening, and strong credential management.
What is the exposure or risk?
Organizations face the greatest risk when internet-facing IoT or Linux devices have Telnet enabled, use weak credentials, or run outdated firmware and operating systems. Once compromised, devices can become part of a botnet used for large-scale DDoS attacks and other malicious activity. Because KATARU includes privilege-escalation and persistence capabilities, infections can survive reboots and remain difficult to remove.
The malware affects a wide range of Linux-based devices, including routers, IoT equipment, and other connected systems. Unpatched or unsupported devices may provide attackers with a long-term foothold in the environment.
What are the recommendations?
Barracuda recommends the following actions to reduce risk:
- Disable Telnet and secure remote access. Use SSH or other secure management methods and restrict access to trusted networks or VPNs.
- Use strong, unique credentials. Remove default passwords and limit administrative access where possible.
- Update firmware and Linux kernels. Apply the latest security updates to Linux-based devices.
- Segment IoT and OT networks. Restrict unnecessary communication and limit direct internet access.
- Isolate and rebuild compromised devices. Disconnect affected systems, perform a factory reset or reimage, and apply security updates before reconnecting.
- Replace unsupported devices. Retire hardware that can no longer receive security updates or be securely configured.
References
For more in-depth information about the recommendations, please visit the following link:
If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.

