LIVE NEWS
  • Capricor’s data clash with the FDA| STAT
  • I’ve complained about Windows Search for years, and Microsoft’s latest fix addresses every frustration at once
  • Anthropic says Claude ‘gained unauthorized access’ to others’ systems
  • Anthropic backs urgent call for the most powerful AI labs to hit the brakes
  • Decadal sink-source shifts of forest aboveground carbon since 1988
  • Diane Abbott and Joani Reid readmitted as Labour MPs | Labour
  • China pushes harder in South China Sea – as attention drifts away
  • What if the brain does not create consciousness?
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Tengu botnet reboots Linux devices to survive removal
Cybersecurity

Tengu botnet reboots Linux devices to survive removal

primereportsBy primereportsJuly 29, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Tengu botnet reboots Linux devices to survive removal
Share
Facebook Twitter LinkedIn Pinterest Email


A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found.

The malware, dubbed Tengu, was discovered by a machine-learning system the company uses to identify malware families that do not match known signatures.

Researchers first observed the dropper reaching their honeypots through Telnet credential brute-force attacks.

Tengu isn’t just another Mirai variant

Nozomi’s analysis found a range of capabilities built into the malware, including an encrypted channel for issuing commands, the ability to relay an operator’s traffic through the infected device, delivery of new payloads, collection of system and network details, and a wide set of denial-of-service functions covering several protocols.

“It also includes multiple persistence and self-defense mechanisms designed to keep the malware running on compromised Linux-based devices and make recovery more difficult,” the researchers wrote.

Tengu retains several Mirai characteristics, including plaintext registration messages and reused denial-of-service code. It also adds a SOCKS5 proxy, shell command execution, system and network reconnaissance, and the ability to download ELF binaries or Android APKs through an IPFS gateway hosted on the same command-and-control (C2) server.

Researchers believe the APK support targets poorly secured Android TV boxes and similar Android-based devices. The malware also includes 25 DDoS methods.

Built to survive removal

Besides persistence through systemd and init.d, two Linux systems that automatically launch services when a device starts up, Tengu tries to use cron, the tool for scheduling recurring tasks, though Nozomi found this method doesn’t work as intended. The malware creates a hidden guardian process that checks every 60 seconds whether the main malware process is still running and restarts it if necessary.

Tengu also abuses the Linux hardware watchdog. A background process disguised as a kernel worker thread feeds the watchdog only while Tengu is running. If defenders terminate the main process, the watchdog is no longer refreshed and reboots the device after about 30 seconds, giving the malware another opportunity to restore itself.

Tengu botnet reboots Linux devices to survive removal

Watchdog handling function (Source: Nozomi Networks)

The malware overwrites reboot and shutdown binaries with the string ELFOOD, preventing administrators from restarting or powering down an infected system through the standard commands. Another process repeatedly scans running processes and terminates competing botnets.

“Most Mirai variants implement few, if any, of these self-defense capabilities,” Nozomi said.

To reduce the chance of detection, Tengu decrypts its strings only during execution, can operate from memory, renames its process to systemd-journald, checks whether a debugger is attached to it, looks for environment variables associated with hooking tools, measures instruction timing to detect emulation and periodically verifies the integrity of its own code.

What defenders can do

Nozomi did not identify the threat actor behind Tengu or estimate the number of infected devices. The company recommends applying security updates, replacing default credentials, segmenting networks and monitoring Linux-based and IoT devices for unusual activity.

Nozomi also published indicators of compromise (IoCs), including the malware’s C2 address and sample hashes for six processor architectures, along with a MITRE ATT&CK mapping of Tengu’s tactics and techniques.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Article44 states say CFTC has no authority over sports prediction markets
Next Article U.S. Debt Refinancing Burdens Grow as Treasury Yields Reach Multi-Decade Peaks
primereports
  • Website

Related Posts

Cybersecurity

JetBrains warns of critical TeamCity remote code execution flaw

July 30, 2026
Cybersecurity

SE Asian Cybercriminal Syndicates Become a Global Power

July 30, 2026
Cybersecurity

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

July 30, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Threat of further violence looms after Mexican cartel rampage

February 25, 202645 Views

‘Two-sided risk’ Medicare Advantage plans improve patient outcomes

February 24, 202622 Views

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202617 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Cybersecurity
  • Crypto
  • Artificial Intelligence
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Capricor’s data clash with the FDA| STAT
  • I’ve complained about Windows Search for years, and Microsoft’s latest fix addresses every frustration at once
  • Anthropic says Claude ‘gained unauthorized access’ to others’ systems
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.