Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Tengu Botnet Uses Watchdog to Restart Linux Devices

Tengu Botnet Uses Watchdog to Restart Linux Devices

Posted on July 28, 2026 By CWS

A newly identified botnet, Tengu, derived from the notorious Mirai, has been discovered by researchers to have a unique ability to use the hardware watchdog of infected Linux devices to initiate a reboot when its primary process is terminated. This allows its persistence mechanisms to reattempt launching, posing a significant challenge for cybersecurity defenders.

Technical Capabilities of Tengu

Tengu’s arsenal includes 25 different methods for launching distributed denial-of-service (DDoS) attacks. Additionally, it is capable of configuring a SOCKS5 proxy, executing shell commands, and gathering system and network information. The malware has the ability to self-update and download additional Executable and Linkable Format (ELF) or Android package (APK) payloads as needed.

Nozomi Networks Labs, the entity behind the research, has identified Tengu samples compatible with various architectures, including i386, amd64, MIPS, ARM, PowerPC, and m68k. However, the report did not specify any particular vendor or device model, nor did it provide details about the botnet’s operator, the number of infections, or any real-world DDoS incidents linked to Tengu.

Recommendations for Defenders

To combat the threat posed by Tengu, experts recommend several defensive measures. These include disabling internet access for Telnet and other non-essential administrative services, changing default credentials, updating device firmware, and segmenting Internet of Things (IoT) networks. A thorough review of systemd services, init scripts, shell startup files, and cron-related paths is advised before restoring a potentially compromised device to operation.

Published on July 27, 2026, Nozomi’s analysis highlights Tengu’s notable persistence and self-defense strategies, which set it apart from other Mirai-derived malware. A key feature is a guardian process that monitors the main malware process every minute, restarting it if necessary. This is complemented by mechanisms to create fake system services, modify startup scripts, and employ cron jobs, although some elements of the cron setup appear incomplete.

How Tengu Exploits Watchdog Timers

One of Tengu’s advanced features involves manipulating the device’s hardware watchdog. It operates a background process that impersonates [kworker/0:0], reactivating the watchdog device, setting a timeout, and maintaining keepalive signals while the malware process is running. If the process is terminated, the absence of these signals leads to a device reboot, allowing Tengu’s persistence tactics another opportunity to activate.

The malware also disrupts standard system operations by altering ELF headers of reboot and shutdown utilities, potentially hindering defenders’ efforts to safely restart or power down compromised systems. Communication with a command-and-control (C2) server at 64[.]89.163.8 over TCP port 9931 is established, with plaintext data for registration and heartbeat traffic, while commands and updates are encrypted using a custom scheme similar to ChaCha20/Poly1305.

Ongoing Investigations and Findings

Further research by URLhaus indicates 17 malicious URLs connected to the IP address 64[.]89.163.8, suggesting a broader malicious infrastructure. These records, which include various payloads, have been documented since June 17, 2026, though none are confirmed as Tengu by URLhaus. The investigation continues to determine the reach and impact of Tengu’s operations, with ongoing efforts to uncover more details about its scale and infrastructure.

The Hacker News has approached Nozomi Networks for further insights into Tengu’s operational scope and infrastructure, with updates to follow as new information becomes available. Meanwhile, defenders are urged to remain vigilant and employ comprehensive security measures to mitigate potential threats from this resilient botnet.

The Hacker News Tags:botnet analysis, C2 communication, Cybersecurity, DDoS attack, endpoint security, IoT security, Linux security, malware persistence, Mirai variant, network defense, Nozomi Networks, system integrity, Telnet brute force, Tengu botnet, watchdog timer

Post navigation

Previous Post: Origin Energy Reports Data Breach Impacting 900,000 Customers
Next Post: Apple Resolves Numerous Security Flaws in Latest Updates

Related Posts

Critical Linux Vulnerability Exposes Systems to Root Attacks Critical Linux Vulnerability Exposes Systems to Root Attacks The Hacker News
Linux Kernel Vulnerabilities Highlight Security Concerns Linux Kernel Vulnerabilities Highlight Security Concerns The Hacker News
Microsoft Alerts on OAuth Redirect Exploitation in Phishing Attacks Microsoft Alerts on OAuth Redirect Exploitation in Phishing Attacks The Hacker News
WebRTC Skimmer Evades CSP to Steal E-Commerce Data WebRTC Skimmer Evades CSP to Steal E-Commerce Data The Hacker News
Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants The Hacker News
LLM Agent Exploitation Follows Marimo Vulnerability Attack LLM Agent Exploitation Follows Marimo Vulnerability Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple’s iOS 26.6 Patch Secures Against Critical Vulnerabilities
  • Hush Security Secures $30M for AI Governance Innovation
  • Over 24,000 BMCs Expose IPMI Passwords: Security Alert
  • Aembit Partners with Snowflake for AI Security Enhancement
  • Apple Resolves Numerous Security Flaws in Latest Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple’s iOS 26.6 Patch Secures Against Critical Vulnerabilities
  • Hush Security Secures $30M for AI Governance Innovation
  • Over 24,000 BMCs Expose IPMI Passwords: Security Alert
  • Aembit Partners with Snowflake for AI Security Enhancement
  • Apple Resolves Numerous Security Flaws in Latest Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark