Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Tengu Botnet Enhances IoT Device Resilience

New Tengu Botnet Enhances IoT Device Resilience

Posted on July 28, 2026 By CWS

The Tengu botnet, based on the Mirai framework, has emerged as a formidable threat to Internet of Things (IoT) devices, making them increasingly difficult to sanitize once infected. Targeting Linux-based systems with exposed Telnet or remote administration services, Tengu fortifies these devices against standard removal attempts.

Understanding Tengu’s Strategy

Tengu employs traditional tactics of the Mirai botnet by seeking out devices with inadequate protection. However, it introduces enhanced defenses against interference. Devices like routers, cameras, and DVRs, which often suffer from outdated firmware or default credentials, become prime targets.

The botnet’s persistence is underscored by its ability to reboot a device during attempts to eliminate the malware, complicating efforts to secure affected systems. Researchers at Nozomi Networks have highlighted this capability, which misleads administrators into thinking a simple restart resolves the issue.

Mechanisms of Persistence

Tengu distinguishes itself by monitoring its operational state and detecting unauthorized changes. It utilizes Linux proc filesystem memory-mapping information to establish a baseline SHA-256 checksum, constantly verifying this to identify any tampering. This vigilance is coupled with checks for writable memory mappings, indicating potential analysis attempts.

If tampering is detected, Tengu can initiate a device reboot, erasing temporary traces and disrupting cleanup activities. This persistence necessitates comprehensive examination of systemd services, init scripts, and other crucial files before restoring an affected device.

Mitigating Exposure Risks

Primarily targeting IoT devices with exposed Telnet or administrative services, Tengu exploits weak credential practices and inadequate device management. Older network equipment, such as vulnerable web cameras and DVRs, remains particularly susceptible.

Organizations can mitigate risks by minimizing public exposure, disabling unnecessary remote access, and replacing default passwords with robust alternatives. Keeping firmware updated and isolating IoT devices from critical networks can further reduce vulnerability.

Security teams should remain vigilant for unexpected network activity and unusual process behaviors, ensuring thorough reviews of persistence locations. This is crucial as modern botnets increasingly integrate long-term access with distributed denial-of-service (DDoS) capabilities, posing significant operational risks.

In conclusion, the Tengu botnet exemplifies the evolving challenges in IoT security, demanding proactive defense strategies to safeguard against such persistent threats.

Cyber Security News Tags:botnet defense, Cybersecurity, device protection, IoT devices, IoT security, Linux systems, malware removal, Mirai botnet, network security, Tengu botnet

Post navigation

Previous Post: Frenos Secures $1.52M to Enhance OT Security Innovations
Next Post: OpenAI Exploits Artifactory Flaw Before Hugging Face Breach

Related Posts

Closing the Costly SOC Triage-to-Response Gap Closing the Costly SOC Triage-to-Response Gap Cyber Security News
Incident Response Planning – Preparing for Data Breaches Incident Response Planning – Preparing for Data Breaches Cyber Security News
Ransomware Gangs Leveraging RMM Tools to Attack Organizations and Exfiltrate Data Ransomware Gangs Leveraging RMM Tools to Attack Organizations and Exfiltrate Data Cyber Security News
Claude Cowork Enhances AI Session Management on Mobile Claude Cowork Enhances AI Session Management on Mobile Cyber Security News
Microsoft 365 Outage Disrupts North American Admin Access Microsoft 365 Outage Disrupts North American Admin Access Cyber Security News
MastaStealer Weaponizes Windows LNK Files, Executes PowerShell Command, and Evades Defender MastaStealer Weaponizes Windows LNK Files, Executes PowerShell Command, and Evades Defender Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark