ESET researchers have identified a new and improved version of Kaiten, a malware controlled via Internet Relay Chat (IRC) that is commonly used for distributed denial-of-service (DDoS) attacks. 
The new version of the malware has been dubbed “KTN-Remastered” or “KTN-RM,” while ESET researchers have already identified three versions of Linux/Remaiten. Based on the artifacts found within the code, the main feature of the malware is its improved propagation mechanism.
Based primarily on Linux/Gafgyt telnet scanning , KTN-RM (Kaiten) improves its propagation mechanism by using executable binary downloaders for embedded platforms, such as routers and other connected devices, while primarily targeting instances with weak login credentials.
“In addition, the downloader ’s job is to request the Command & Control server for the Linux/Remaiten bot binary for its current architecture. When executed, it creates another bot that its creators can use maliciously. We have seen this technique used by Linux/Moose for propagation before,” notes Michal Malík, Malware Researcher at ESET.
In a strange twist, this strain of malware also has a message for those who might try to neutralize it.
“ In the welcome message, version 2.0 seems to single out malwaremustdie.org which has published extensive details about Gafgyt , Tsunami and other members of this malware family , ” Malík adds .
Additional information about the Linux/Remaiten Bot is available in technical article on ESET's official security blog, WeLiveSecurity.com.
