A newly identified IoT malware family named KATARU is targeting internet-facing Linux devices, aiming to integrate them into Mirai-style DDoS botnets. The malware commonly exploits exposed Telnet services that are protected by weak or default credentials, as outlined in Smarter MSP.KATARU gains initial access by exploiting exposed Telnet services with weak credentials on Linux devices. Once inside, it downloads and executes a malicious payload, then attempts to escalate privileges to root using known Linux exploits. To ensure long-term control, KATARU establishes persistence mechanisms that survive device reboots. It utilizes encrypted command-and-control communications to evade detection, enabling it to launch Distributed Denial of Service (DDoS) attacks, conduct SSH brute-force activities, execute remote commands, and download additional malware.The threat is particularly noteworthy as it combines common security vulnerabilities like exposed Telnet and weak passwords with modern malware tactics such as encrypted C2 and persistent root access. Organizations with internet-facing IoT or Linux devices using Telnet, weak credentials, or outdated software are at the highest risk. Compromised devices can be used for large-scale DDoS attacks, and the malware's persistence features make infections difficult to remove.Source: Smarter MSP