As cited
Copy frozen at (site build).
threat intel
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
Tengu is a Mirai-derived botnet targeting Linux systems that leverages hardware watchdog functionality to reboot compromised devices when its process is terminated, allowing persistence mechanisms to re-execute the malware. Nozomi Networks Labs detected the dropper via Telnet credential brute force attacks and confirmed the botnet supports at least 25 distributed denial-of-service attack types.
Why it matters: Linux infrastructure operators need to monitor for Telnet brute force activity and implement watchdog timeout controls to prevent automatic reboots that aid malware persistence and DDoS attack staging.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
Tengu, a Mirai-derived botnet, exploits Linux hardware watchdogs to automatically reboot compromised devices when its main process is terminated, allowing persistence mechanisms to restart it. The malware was observed entering systems through Telnet credential brute-force attacks and supports 25 distributed denial-of-service attack vectors.
Why it matters: Linux administrators and defenders must secure Telnet access, disable unnecessary hardware watchdog features, and implement monitoring for unexpected reboots, as Tengu's reboot evasion technique complicates traditional process-killing remediation.
- Source published
- First seen by Cybersecurity Tracker