Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Linux Malware Tengu Hides as Kernel Process

New Linux Malware Tengu Hides as Kernel Process

Posted on September 7, 2026 By CWS

Introduction to Tengu Malware

The emergence of a new Linux malware named Tengu is raising alarms in cybersecurity circles. This malicious bot is engineered to remain undetected, transforming compromised systems into instruments of attack. By masquerading as a typical kernel process, Tengu maintains persistence across diverse Linux environments and is capable of orchestrating distributed denial-of-service (DDoS) attacks.

Targeting both servers and IoT devices, Tengu presents a significant threat. Its capabilities extend beyond simple denial-of-service tools, utilizing raw UDP floods, SSH handshakes, and web-request generation to disrupt targeted networks. The exact method of initial compromise remains unknown, adding a layer of complexity to defense strategies.

Features and Persistence

Reverser.space’s analysis, shared with Cyber Security News, reveals that Tengu is a stripped, statically linked 32-bit Linux ELF, specifically designed for servers and IoT environments. Despite its complex feature set, its lineage to other malware like Mirai is not definitively established. However, its stealth and persistence mechanisms pose a significant threat.

Tengu’s ability to disguise itself as a kernel worker allows it to evade detection during standard system checks. The malware also ensures its survival through various startup scripts and services, making it difficult to eradicate once entrenched. This adaptability is critical in its operation across different platforms and systems.

Kernel Process Masquerading

To blend in with legitimate processes, Tengu adopts a randomized kernel-worker-style name. This deceptive tactic reduces its visibility in process listings. Furthermore, Tengu manipulates the operating system’s out-of-memory controls to avoid termination under memory pressure, ensuring its continuous operation.

The malware also manages to persist through reboots by leveraging systemd services, SysV scripts, and other startup mechanisms. This resilience was highlighted in reports of Tengu operations targeting internet-exposed embedded Linux devices, emphasizing its cross-platform reach.

DDoS and Network Disruption

Tengu’s DDoS capabilities include two modes of UDP attack. One mode creates raw IPv4 packets with customizable headers, while the other utilizes standard datagram sockets as a fallback. These tactics, combined with SSH handshake activities, enable it to exhaust network resources and disrupt web services.

Security teams must remain vigilant for unusual network behaviors, such as unexpected UDP traffic or SSH handshake anomalies. Monitoring for these indicators can help in early detection and mitigation of Tengu’s impacts.

Conclusion and Recommendations

The Tengu malware underscores the evolving threat landscape for Linux and IoT devices. Its stealth, persistence, and multifaceted attack strategies highlight the necessity for robust cybersecurity defenses. Administrators should isolate suspected infections, secure network access, and regularly update systems to mitigate risks.

Continuous monitoring for indicators of compromise, such as unexpected process names or network anomalies, is essential in identifying and neutralizing threats posed by Tengu. Proactive measures, including patching vulnerabilities and restricting unnecessary remote access, can further reduce the likelihood of new infections.

Cyber Security News Tags:Cybersecurity, DDoS attacks, embedded systems, IoT, kernel process, Linux, Malware, network security, Servers, Tengu

Post navigation

Previous Post: ConnectWise Highlights ScreenConnect Security Issue
Next Post: OpenAI Pledges $1 Billion for AI Cybersecurity Tools

Related Posts

New Supply Chain Attack Hits npm, PyPI, and Crates New Supply Chain Attack Hits npm, PyPI, and Crates Cyber Security News
Hackers Mimic IT Teams to Exploit Microsoft Teams Request to Gain System Remote Access Hackers Mimic IT Teams to Exploit Microsoft Teams Request to Gain System Remote Access Cyber Security News
Microsoft Trials AI Tool to Diagnose Windows 11 Slowdowns Microsoft Trials AI Tool to Diagnose Windows 11 Slowdowns Cyber Security News
DPRK-Linked Malicious macOS Installers Steal Credentials DPRK-Linked Malicious macOS Installers Steal Credentials Cyber Security News
Cybercriminals Exploit AI to Distribute macOS Malware Cybercriminals Exploit AI to Distribute macOS Malware Cyber Security News
48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild 48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027
  • Sensitive Employee Data Breach at Natural Resources Wales

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027
  • Sensitive Employee Data Breach at Natural Resources Wales

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark