Turf War in Your Living Room: ‘Katana’ Botnet Hijacks Android TV Boxes with Custom Rootkits
ID: 21411ded-4625-5f9b-8379-79cf2cca3201
STIX ID: report--21411ded-4625-5f9b-8379-79cf2cca3201
Feed Name: securityonline.info
Nokia ERT reports a Mirai variant called Katana actively infecting unbranded Android TV boxes by leveraging unauthenticated ADB access obtained through residential proxies; Katana performs aggressive bot-killing and ADB port remapping to seize devices and uniquely compiles a kernel Loadable Kernel Module on-device (via TinyCC) for stealthy, long-term persistence, while conducting IPv4-only spoofed attacks. Recommended mitigations include using Google-certified hardware, disabling network ADB/Developer options, and monitoring router-connected devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
