< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Tengu Botnet Exploits Linux Watchdog to Persist and Launch DDoS Attacks

Researchers at Nozomi Networks Labs disclosed a new Mirai‑derived botnet, called Tengu, that targets Linux devices. Tengu gains access via Telnet credential‑brute‑force and then uses a hardware watchdog timer to reboot the device when its main process is killed, allowing its other persistence components to restart automatically.

The botnet supports 25 DDoS methods, runs a SOCKS5 proxy, can execute shell commands and download additional ELF or Android APK payloads. It contacts a hard‑coded command‑and‑control server at 64.89.163.8 on TCP port 9931, using plaintext registration and ChaCha20/Poly1305‑encrypted commands, and can retrieve files from an IPFS gateway. Nozomi recommends disabling Telnet, removing default credentials, updating firmware and segmenting IoT networks. Infections have not been quantified.

Entities

Linux operating system · Mirai botnet · Nozomi Networks Labs · Telnet protocol · Tengu botnet

Sources

16 days ago