Ethical Hacking News
A new Mirai-derived malware variant known as Tengu has emerged as a significant threat to Linux device security. By exploiting compromised devices' hardware watchdogs and leveraging persistence mechanisms, the Tengu botnet can ensure its survival even in the face of defensive measures.
The Tengu botnet is a Mirai-derived malware variant that poses a significant threat to Linux device security. The malware can persist on compromised devices even after its primary process is terminated by exploiting the hardware watchdog feature. The Tengu botnet supports 25 distributed denial-of-service (DDoS) methods and can launch coordinated attacks. The malware can run a SOCKS5 proxy, execute shell commands, and collect system and network data. The Tengu botnet is highly adaptable and difficult to contain due to its ability to update its own code and retrieve new payloads.
The cybersecurity landscape has recently witnessed the emergence of a new and highly concerning malware variant, dubbed Tengu. This Mirai-derived botnet has been observed to exhibit a unique set of characteristics that make it particularly hazardous to compromised Linux devices. In this article, we will delve into the details of the Tengu botnet, its tactics, techniques, and procedures (TTPs), and the implications for endpoint security.
According to recent research by Nozomi Networks Labs, the Tengu botnet can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. This cleverly designed mechanism allows the malware to persist on the compromised device even after its primary process is terminated. The Tengu botnet also supports 25 distributed denial-of-service (DDoS) methods, making it a formidable threat in terms of its ability to launch coordinated attacks.
Furthermore, the Tengu botnet can run a SOCKS5 proxy, execute shell commands, and collect system and network data. It can also update itself and retrieve additional Executable and Linkable Format (ELF) or Android package (APK) payloads. The malware's ability to update its own code and retrieve new payloads makes it highly adaptable and difficult to contain.
Nozomi Networks Labs observed that the Tengu dropper reached its honeypots through Telnet credential brute force, highlighting the importance of securing administrative services and default credentials on Linux devices. The researchers also noted that the malware can create a fake systemd service, add init and RC scripts, alter shell startup files, and mark its installed binary immutable.
Another fascinating aspect of the Tengu botnet is its use of a hardware watchdog to reboot compromised devices. By abusing this feature, the malware can ensure its persistence even in the face of defensive measures. The researchers also found that the Tengu botnet carries a hardcoded list of reboot and shutdown utilities, which it overwrites with the string ELFOOD.
The analyzed sample was configured to communicate with a command-and-control (C2) server at 64[.]89.163.8 over TCP port 9931. Registration, heartbeat traffic, and command output are sent in plaintext, while server commands and updates use a custom ChaCha20/Poly1305-like authenticated encryption scheme.
Interestingly, URLhaus independently recorded 17 malware URLs at 64[.]89.163.8 beginning June 17, 2026. However, these records did not identify the files as Tengu, as no matching SHA-256 hashes were found. The researchers concluded that while the C2 service on port 9931 and the IPFS gateway on port 8080 may be reachable, there is currently limited information available about the Tengu botnet's observed scale, infrastructure status, or sample linkage.
In light of this emerging threat, defenders should take immediate action to secure their Linux devices. This includes removing internet exposure for Telnet and other unnecessary administrative services, replacing default credentials, updating firmware, segmenting Internet of Things (IoT) networks, and reviewing systemd services, init scripts, shell startup files, and cron-related paths.
Furthermore, it is essential to recognize the potential vulnerabilities of poorly secured Android TV boxes or similar devices. The Tengu botnet's ability to target these devices highlights the need for enhanced security measures in IoT environments.
In conclusion, the Tengu botnet represents a significant threat to Linux device security, particularly due to its use of a hardware watchdog and persistence mechanisms. As this emerging threat continues to evolve, it is crucial that defenders remain vigilant and proactive in securing their endpoints against such malicious activities.
A new Mirai-derived malware variant known as Tengu has emerged as a significant threat to Linux device security. By exploiting compromised devices' hardware watchdogs and leveraging persistence mechanisms, the Tengu botnet can ensure its survival even in the face of defensive measures.
Related Information:
https://www.ethicalhackingnews.com/articles/Tengu-Botnet-A-Mirai-Derived-Malware-Threat-to-Linux-Devices-ehn.shtml
https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html
Published: Tue Jul 28 11:30:51 2026 by llama3.2 3B Q4_K_M