Back to News
Threat Intelligence

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Cyber RTJuly 28, 20263 min read
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Tengu, a new Mirai-derived botnet, uses a compromised Linux device's hardware watchdog to reboot if its main process is killed, allowing its persistence mechanisms to relaunch it. It supports 25 DDoS methods, runs a SOCKS5 proxy, executes shell commands, and collects data. Nozomi Networks Labs observed it via Telnet brute force. Defenders should secure devices by removing internet exposure, updating firmware, and reviewing system configurations.

A new botnet variant called Tengu, derived from the notorious Mirai malware, has been discovered with enhanced persistence mechanisms that make it particularly resilient against defensive measures. Tengu can exploit the hardware watchdog of compromised Linux devices to trigger a reboot if its main process is terminated. This reboot allows Tengu's other persistence mechanisms to attempt a relaunch, making it difficult for defenders to completely remove the malware. The initial infection vector for Tengu involves brute-forcing Telnet credentials, as observed by Nozomi Networks Labs. Tengu is equipped with a variety of capabilities, supporting 25 different distributed denial-of-service (DDoS) methods, running a SOCKS5 proxy, executing shell commands, and collecting system and network data. It can also update itself and download additional payloads in Executable and Linkable Format (ELF) or Android package (APK) formats. Nozomi Networks identified samples for several architectures, including i386, amd64, MIPS, ARM, PowerPC, and m68k, but did not specify any particular vendor or device model affected. To mitigate the threat posed by Tengu, defenders are advised to remove internet exposure for Telnet and other unnecessary administrative services, replace default credentials, update firmware, segment IoT networks, and review systemd services, init scripts, shell startup files, and cron-related paths. These measures can help prevent the initial compromise and persistence of the malware on devices. Nozomi Networks Labs published their analysis of Tengu on July 27, 2026, highlighting its advanced persistence and self-defense capabilities, which distinguish it from other Mirai-derived variants. The botnet employs a guardian process that checks the main malware process every 60 seconds, relaunching it if necessary. It can also create fake systemd services, add init and RC scripts, modify shell startup files, and mark its installed binary as immutable. A cron-based persistence routine is present, but appears to be incomplete or malfunctioning. Tengu also utilizes a second persistence mechanism by exploiting the device's hardware watchdog. A background worker, disguised as [kworker/0:0], reopens the watchdog device, arms it with a 30-second timeout, and sends keepalive signals while the main malware process is active. If the process is killed, the watchdog stops receiving signals, allowing the device to reboot and giving Tengu another chance to relaunch. Additionally, Tengu carries a hardcoded list of reboot and shutdown utilities, overwriting their ELF headers with the string ELFOOD. This can interfere with normal commands that defenders might use to restart or safely power down a compromised device. The botnet communicates with a command-and-control (C2) server at 64[.]89.163.8 over TCP port 9931, using plaintext for registration and heartbeat traffic, while employing a custom encryption scheme for server commands and updates. Tengu can also obtain a content identifier from an InterPlanetary File System (IPFS) gateway on the same server, validate the result as an ELF or APK, and execute or install it. Nozomi Networks suggests that the APK path likely targets poorly secured Android TV boxes or similar devices, though no confirmed Android victims have been documented. URLhaus recorded 17 malware URLs associated with the C2 server, but did not specifically identify them as Tengu-related. As of July 28, these URLs were offline, and none of the SHA-256 hashes matched the sample hash published by Nozomi. The Hacker News has reached out to Nozomi Networks for further details on Tengu's scale and infrastructure status.