Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Tengu Botnet Uses Watchdog to Restart Linux Devices

Tengu Botnet Uses Watchdog to Restart Linux Devices

Posted on July 28, 2026 By CWS

A newly identified botnet, Tengu, derived from the notorious Mirai, has been discovered by researchers to have a unique ability to use the hardware watchdog of infected Linux devices to initiate a reboot when its primary process is terminated. This allows its persistence mechanisms to reattempt launching, posing a significant challenge for cybersecurity defenders.

Technical Capabilities of Tengu

Tengu’s arsenal includes 25 different methods for launching distributed denial-of-service (DDoS) attacks. Additionally, it is capable of configuring a SOCKS5 proxy, executing shell commands, and gathering system and network information. The malware has the ability to self-update and download additional Executable and Linkable Format (ELF) or Android package (APK) payloads as needed.

Nozomi Networks Labs, the entity behind the research, has identified Tengu samples compatible with various architectures, including i386, amd64, MIPS, ARM, PowerPC, and m68k. However, the report did not specify any particular vendor or device model, nor did it provide details about the botnet’s operator, the number of infections, or any real-world DDoS incidents linked to Tengu.

Recommendations for Defenders

To combat the threat posed by Tengu, experts recommend several defensive measures. These include disabling internet access for Telnet and other non-essential administrative services, changing default credentials, updating device firmware, and segmenting Internet of Things (IoT) networks. A thorough review of systemd services, init scripts, shell startup files, and cron-related paths is advised before restoring a potentially compromised device to operation.

Published on July 27, 2026, Nozomi’s analysis highlights Tengu’s notable persistence and self-defense strategies, which set it apart from other Mirai-derived malware. A key feature is a guardian process that monitors the main malware process every minute, restarting it if necessary. This is complemented by mechanisms to create fake system services, modify startup scripts, and employ cron jobs, although some elements of the cron setup appear incomplete.

How Tengu Exploits Watchdog Timers

One of Tengu’s advanced features involves manipulating the device’s hardware watchdog. It operates a background process that impersonates [kworker/0:0], reactivating the watchdog device, setting a timeout, and maintaining keepalive signals while the malware process is running. If the process is terminated, the absence of these signals leads to a device reboot, allowing Tengu’s persistence tactics another opportunity to activate.

The malware also disrupts standard system operations by altering ELF headers of reboot and shutdown utilities, potentially hindering defenders’ efforts to safely restart or power down compromised systems. Communication with a command-and-control (C2) server at 64[.]89.163.8 over TCP port 9931 is established, with plaintext data for registration and heartbeat traffic, while commands and updates are encrypted using a custom scheme similar to ChaCha20/Poly1305.

Ongoing Investigations and Findings

Further research by URLhaus indicates 17 malicious URLs connected to the IP address 64[.]89.163.8, suggesting a broader malicious infrastructure. These records, which include various payloads, have been documented since June 17, 2026, though none are confirmed as Tengu by URLhaus. The investigation continues to determine the reach and impact of Tengu’s operations, with ongoing efforts to uncover more details about its scale and infrastructure.

The Hacker News has approached Nozomi Networks for further insights into Tengu’s operational scope and infrastructure, with updates to follow as new information becomes available. Meanwhile, defenders are urged to remain vigilant and employ comprehensive security measures to mitigate potential threats from this resilient botnet.

The Hacker News Tags:botnet analysis, C2 communication, Cybersecurity, DDoS attack, endpoint security, IoT security, Linux security, malware persistence, Mirai variant, network defense, Nozomi Networks, system integrity, Telnet brute force, Tengu botnet, watchdog timer

Post navigation

Previous Post: Origin Energy Reports Data Breach Impacting 900,000 Customers
Next Post: Apple Resolves Numerous Security Flaws in Latest Updates

Related Posts

737 VPN Extensions Expose Users to Proxy Risks 737 VPN Extensions Expose Users to Proxy Risks The Hacker News
Cybersecurity Concerns Rise: Deceptive Extensions and Phishing Tactics Cybersecurity Concerns Rise: Deceptive Extensions and Phishing Tactics The Hacker News
Microsoft and CrowdStrike Launch Shared Threat Actor Glossary to Cut Attribution Confusion Microsoft and CrowdStrike Launch Shared Threat Actor Glossary to Cut Attribution Confusion The Hacker News
TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks The Hacker News
Cline CLI Supply Chain Breach Installs OpenClaw Cline CLI Supply Chain Breach Installs OpenClaw The Hacker News
CISA Red Team Exposes Security Gaps in Key Infrastructure CISA Red Team Exposes Security Gaps in Key Infrastructure The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing
  • Critical GitLab Vulnerability Under Active Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing
  • Critical GitLab Vulnerability Under Active Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark