logo

Turf War in Your Living Room: ‘Katana’ Botnet Hijacks Android TV Boxes with Custom Rootkits

ID: 21411ded-4625-5f9b-8379-79cf2cca3201

STIX ID: report--21411ded-4625-5f9b-8379-79cf2cca3201

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-22

Date Updated: 2026-04-23

Author: Ddos

...
...

Nokia ERT reports a Mirai variant called Katana actively infecting unbranded Android TV boxes by leveraging unauthenticated ADB access obtained through residential proxies; Katana performs aggressive bot-killing and ADB port remapping to seize devices and uniquely compiles a kernel Loadable Kernel Module on-device (via TinyCC) for stealthy, long-term persistence, while conducting IPv4-only spoofed attacks. Recommended mitigations include using Google-certified hardware, disabling network ADB/Developer options, and monitoring router-connected devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.