#ParsedReport #CompletenessHigh
11-09-2026
KATARU: IoT Malware Adopts Public LPE Exploits
https://www.nozominetworks.com/blog/kataru-iot-malware-adopts-public-lpe-exploits
Report completeness: High
Threats:
Kataru
Fragnesia_vuln
Dirtyfrag_vuln
Copyfail_vuln
Dnsflood_technique
Mirai
Icmpflood_technique
Httpflood_technique
Tengu_botnet
Victims:
Internet of things devices, Linux systems, Embedded devices, Routers, Android devices
Industry:
Iot
Geo:
Vietnam
CVEs:
CVE-2026-43284 [Vulners]
CVSS V3.1: 8.8,
Vulners: Exploitation: True
Soft:
- linux linux_kernel (<5.10.255, <5.15.205, <6.1.171, <6.6.138, <6.12.87)
CVE-2026-46300 [Vulners]
CVSS V3.1: 7.8,
Vulners: Exploitation: True
Soft:
- linux linux_kernel (le5.10.257, <5.15.208, <6.1.174, <6.6.141, <6.12.91)
CVE-2026-31431 [Vulners]
CVSS V3.1: 7.8,
Vulners: Exploitation: True
Soft:
- linux linux_kernel (<5.10.254, <5.15.204, <6.1.170, <6.6.137, <6.12.85)
TTPs:
Tactics: 7
Technics: 16
IOCs:
Hash: 5
File: 5
IP: 1
Soft:
BusyBox, Linux, systemd, OpenWrt, Android, Minecraft, FiveM, WireGuard, Unix, crontab, have more...
Algorithms:
chacha20-poly1305, chacha20, curve25519
Languages:
c_language
Platforms:
arm, x86, amd64, cross-platform
YARA: Found
Post #32382
63