Katana is a Mirai-derived distributed denial-of-service botnet targeting Linux-based embedded and network devices. It has been observed compromising MIPS-based Zyxel firewalls through CVE-2023-28771, an unauthenticated command-injection vulnerability exploited using crafted Internet Key Exchange packets. Successful exploitation retrieves and executes malware payloads, enrolling compromised devices into the botnet.
Analyzed Katana-linked payloads support 11 DDoS methods, including UDP, TCP SYN, TCP ACK, GRE, and socket-based flooding. The malware connects to command-and-control infrastructure, transmits registration information containing execution parameters, and processes commands for attack execution, sleep, keep-alive communication, and connection closure. It also examines its execution environment and terminates when certain execution-path checks are triggered.
Katana has been linked to a Telegram group named “SHINJI.APP | Katana botnet,” where operators advertised attack-method updates matching analyzed payloads. Its infrastructure and attack methods are actively maintained. Abuse of residential-proxy access to exposed device services has also been associated with its distribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Additionally, we discovered a Telegram group called "SHINJI.APP | Katana botnet" that is actively involved in updating the botnet's methods and performing maintenance tasks.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Wrapped around these AI engines are fourteen additional scanning tools... covering the full attack chain from passive reconnaissance to credential brute-forcing and bypass detection.
"Self-updating modules, allowing attackers to rapidly push new exploits as they appear."
“Evasive command-and-control techniques, including domain-fluxing and encrypted command channels.”
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named DDoS botnet that the report assesses was enabled to spread through IPWeb's proxy infrastructure.
Mentioned only because unused strings in KATARU could cause erroneous classification as a Katana variant; no operational use or direct relationship is established.
A modern Mirai fork/strain described as part of the new generation of IoT botnet variants, featuring expanded exploit capabilities, rapid propagation, evasive C2, and modular/self-updating behavior to support sustained DDoS operations.
Modern Mirai fork/variant described as incorporating large IoT exploit libraries, high-speed propagation, evasive C2 (including domain-fluxing/encrypted channels), and self-updating modules to maintain and expand DDoS botnet capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.