Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Tengu Botnet Enhances IoT Device Resilience

New Tengu Botnet Enhances IoT Device Resilience

Posted on July 28, 2026 By CWS

The Tengu botnet, based on the Mirai framework, has emerged as a formidable threat to Internet of Things (IoT) devices, making them increasingly difficult to sanitize once infected. Targeting Linux-based systems with exposed Telnet or remote administration services, Tengu fortifies these devices against standard removal attempts.

Understanding Tengu’s Strategy

Tengu employs traditional tactics of the Mirai botnet by seeking out devices with inadequate protection. However, it introduces enhanced defenses against interference. Devices like routers, cameras, and DVRs, which often suffer from outdated firmware or default credentials, become prime targets.

The botnet’s persistence is underscored by its ability to reboot a device during attempts to eliminate the malware, complicating efforts to secure affected systems. Researchers at Nozomi Networks have highlighted this capability, which misleads administrators into thinking a simple restart resolves the issue.

Mechanisms of Persistence

Tengu distinguishes itself by monitoring its operational state and detecting unauthorized changes. It utilizes Linux proc filesystem memory-mapping information to establish a baseline SHA-256 checksum, constantly verifying this to identify any tampering. This vigilance is coupled with checks for writable memory mappings, indicating potential analysis attempts.

If tampering is detected, Tengu can initiate a device reboot, erasing temporary traces and disrupting cleanup activities. This persistence necessitates comprehensive examination of systemd services, init scripts, and other crucial files before restoring an affected device.

Mitigating Exposure Risks

Primarily targeting IoT devices with exposed Telnet or administrative services, Tengu exploits weak credential practices and inadequate device management. Older network equipment, such as vulnerable web cameras and DVRs, remains particularly susceptible.

Organizations can mitigate risks by minimizing public exposure, disabling unnecessary remote access, and replacing default passwords with robust alternatives. Keeping firmware updated and isolating IoT devices from critical networks can further reduce vulnerability.

Security teams should remain vigilant for unexpected network activity and unusual process behaviors, ensuring thorough reviews of persistence locations. This is crucial as modern botnets increasingly integrate long-term access with distributed denial-of-service (DDoS) capabilities, posing significant operational risks.

In conclusion, the Tengu botnet exemplifies the evolving challenges in IoT security, demanding proactive defense strategies to safeguard against such persistent threats.

Cyber Security News Tags:botnet defense, Cybersecurity, device protection, IoT devices, IoT security, Linux systems, malware removal, Mirai botnet, network security, Tengu botnet

Post navigation

Previous Post: Frenos Secures $1.52M to Enhance OT Security Innovations
Next Post: OpenAI Exploits Artifactory Flaw Before Hugging Face Breach

Related Posts

Earn CPE Credits with SRA’s Purple Team Exercises Earn CPE Credits with SRA’s Purple Team Exercises Cyber Security News
Two Americans Jailed for Assisting North Korean Cyber Operations Two Americans Jailed for Assisting North Korean Cyber Operations Cyber Security News
Earth Ammit Hackers Attacking Using New Tools to Attack Drones Used in Military Sectors Earth Ammit Hackers Attacking Using New Tools to Attack Drones Used in Military Sectors Cyber Security News
Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details Cyber Security News
Threat Actors Using Fake Travel Websites to Infect Users’ PCs with XWorm Malware Threat Actors Using Fake Travel Websites to Infect Users’ PCs with XWorm Malware Cyber Security News
Ransomware Attack Disrupts Washington Hotel Operations in Japan Ransomware Attack Disrupts Washington Hotel Operations in Japan Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Exploits Artifactory Flaw Before Hugging Face Breach
  • New Tengu Botnet Enhances IoT Device Resilience
  • Frenos Secures $1.52M to Enhance OT Security Innovations
  • Nimbus Manticore Targets Critical Sectors with New Malware
  • Chinese Firm Allegedly Builds Network for PLA Cyber Ops

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Exploits Artifactory Flaw Before Hugging Face Breach
  • New Tengu Botnet Enhances IoT Device Resilience
  • Frenos Secures $1.52M to Enhance OT Security Innovations
  • Nimbus Manticore Targets Critical Sectors with New Malware
  • Chinese Firm Allegedly Builds Network for PLA Cyber Ops

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark