Skip to main content
EPSS 99.9%top 0.03%

KATARU: IoT Malware Adopts Public LPE Exploits

0
Medium
Published: 09/11/2026 (09/11/2026, 17:55:38 UTC)
Source: AlienVault OTX General

Description

KATARU is an IoT malware variant discovered in August 2026 through Telnet credential brute-forcing against a honeypot from Vietnam. While maintaining traditional Mirai-style botnet capabilities, it distinguishes itself through an extensive feature set including multiple Linux local privilege escalation exploits, comprehensive persistence mechanisms across Linux and embedded platforms, encrypted C2 communications using X25519 and ChaCha20-Poly1305, anti-analysis techniques, and decoy traffic generation. Implementation artifacts strongly suggest AI-assisted development, evidenced by architecture-mismatched x86 shellcode in ARM binaries, RFC test vectors as configuration values, and untested cross-platform persistence logic. The malware attempts various privilege escalation paths through system misconfigurations and public exploits, establishes persistence across numerous startup mechanisms, and supports multiple DDoS attack vectors alongside SSH brute-forcing capabilities.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 13:05:15 UTC

Technical Analysis

CVE-2026-31431 is a logic flaw in the Linux kernel's cryptographic template involving AF_ALG and splice() that permits an unprivileged local user to perform a deterministic 4-byte write into the system page cache of any readable file. Because the page cache is shared across the host, this can be exploited to escalate privileges to root or escape container boundaries by corrupting in-memory setuid binaries or other sensitive files. This vulnerability affects GKE Standard and Autopilot clusters running Container-Optimized OS, but not containers using GKE Sandbox. Upstream kernel patches have been released and are being incorporated into GKE releases. Mitigations include upgrading to fixed GKE Container-Optimized OS versions or using GKE Sandbox to prevent exploitation.

Potential Impact

An unprivileged local attacker can exploit this vulnerability to write controlled data into the system page cache, potentially leading to local privilege escalation and container escape. This undermines container isolation and can compromise host system security. The vulnerability affects GKE Standard and Autopilot clusters, impacting the security boundary of containers. Containers running with GKE Sandbox are not affected. The impact is rated high due to the potential for root privilege escalation and container breakout.

Defensive Guidance

Upstream kernel patches have been released and are being integrated into GKE releases. Users should upgrade their Container-Optimized OS node pools to the following fixed versions or later: 1.36.0-gke.1555000, 1.35.3-gke.1943000, 1.34.7-gke.1292000, 1.33.11-gke.1132000, 1.32.13-gke.1446000, 1.31.14-gke.1846000, and 1.30.14-gke.2439000. If these versions are not visible in the Google Cloud console, use the gcloud CLI to upgrade node pools and control planes accordingly. In the interim, it is recommended to use GKE Sandbox as a mitigation since containers should not be relied upon as a security boundary due to the prevalence of container breakout vulnerabilities.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.mend.io/blog/phantomraven-wave-5-new-undocumented-npm-supply-chain-campaign-targets-defi-cloud-and-ai-developers/"]
Adversary
PhantomRaven
Pulse Id
69f8acdd6038448e350edbb9

Indicators of Compromise

Domain

ValueDescriptionCopy
domainconsole.info
domainpack.nppacks.com
domainhblnew.ecompk.com
domainecompk.com
domainhblv2.ecompk.com
domainpkg.author.email

Cve

ValueDescriptionCopy
cveCVE-2026-31431

Hash

ValueDescriptionCopy
hash4bdb7aef96dc04c250cceefa222d7d1a
hash83088e7cb00cf9fab74df2f64b7021b2deef6610
hash0ce9b82d290004031b7cc49d724c00011811e1753a283a93a380a311360cfb66
hash78937711bbc74542d304c7a7ea451465a2342438116fb37aa715ccf89b027d04
hashabe9ee9edfc44f7675400207a826c260b2f197d1f93e36010c35d627983e4294

Url

ValueDescriptionCopy
urlhttp://hblnew.ecompk.com/npm/local-rules
urlhttp://pack.nppacks.com/mozbra.php
urlhttp://pack.nppacks.com/npm/
urlhttp://pack.nppacks.com/npm/graphql-js-client-transform
urlhttp://pack.nppacks.com/npm/idle-style-xi
urlhttp://pack.nppacks.com/npm/local-rules
urlhttp://pack.nppacks.com/route.js
urlhttp://pack.nppacks.com/token.php

Threat ID: 69f8af02cbff5d86102ac390

Added to database: 05/04/2026, 14:36:50 UTC

Last enriched: 08/04/2026, 13:05:15 UTC

Last updated: 09/17/2026, 02:23:51 UTC

Views: 706

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses