Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Tengu Botnet Enhances IoT Device Resilience

New Tengu Botnet Enhances IoT Device Resilience

Posted on July 28, 2026 By CWS

The Tengu botnet, based on the Mirai framework, has emerged as a formidable threat to Internet of Things (IoT) devices, making them increasingly difficult to sanitize once infected. Targeting Linux-based systems with exposed Telnet or remote administration services, Tengu fortifies these devices against standard removal attempts.

Understanding Tengu’s Strategy

Tengu employs traditional tactics of the Mirai botnet by seeking out devices with inadequate protection. However, it introduces enhanced defenses against interference. Devices like routers, cameras, and DVRs, which often suffer from outdated firmware or default credentials, become prime targets.

The botnet’s persistence is underscored by its ability to reboot a device during attempts to eliminate the malware, complicating efforts to secure affected systems. Researchers at Nozomi Networks have highlighted this capability, which misleads administrators into thinking a simple restart resolves the issue.

Mechanisms of Persistence

Tengu distinguishes itself by monitoring its operational state and detecting unauthorized changes. It utilizes Linux proc filesystem memory-mapping information to establish a baseline SHA-256 checksum, constantly verifying this to identify any tampering. This vigilance is coupled with checks for writable memory mappings, indicating potential analysis attempts.

If tampering is detected, Tengu can initiate a device reboot, erasing temporary traces and disrupting cleanup activities. This persistence necessitates comprehensive examination of systemd services, init scripts, and other crucial files before restoring an affected device.

Mitigating Exposure Risks

Primarily targeting IoT devices with exposed Telnet or administrative services, Tengu exploits weak credential practices and inadequate device management. Older network equipment, such as vulnerable web cameras and DVRs, remains particularly susceptible.

Organizations can mitigate risks by minimizing public exposure, disabling unnecessary remote access, and replacing default passwords with robust alternatives. Keeping firmware updated and isolating IoT devices from critical networks can further reduce vulnerability.

Security teams should remain vigilant for unexpected network activity and unusual process behaviors, ensuring thorough reviews of persistence locations. This is crucial as modern botnets increasingly integrate long-term access with distributed denial-of-service (DDoS) capabilities, posing significant operational risks.

In conclusion, the Tengu botnet exemplifies the evolving challenges in IoT security, demanding proactive defense strategies to safeguard against such persistent threats.

Cyber Security News Tags:botnet defense, Cybersecurity, device protection, IoT devices, IoT security, Linux systems, malware removal, Mirai botnet, network security, Tengu botnet

Post navigation

Previous Post: Frenos Secures $1.52M to Enhance OT Security Innovations

Related Posts

Critical ASP.NET Vulnerability Allows Attacker To Bypass Security Feature Remotely Critical ASP.NET Vulnerability Allows Attacker To Bypass Security Feature Remotely Cyber Security News
Microsoft Defender Identifies New Trojanized Gaming Tool Threat Microsoft Defender Identifies New Trojanized Gaming Tool Threat Cyber Security News
81% Router Usres Have Not Changed Default Admin Passwords, Exposing Devices to Hackers 81% Router Usres Have Not Changed Default Admin Passwords, Exposing Devices to Hackers Cyber Security News
SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month Cyber Security News
Cybercriminals Exploit Microsoft Tools in New Phishing Scheme Cybercriminals Exploit Microsoft Tools in New Phishing Scheme Cyber Security News
July 2026 SAP Security Updates Address Critical Flaws July 2026 SAP Security Updates Address Critical Flaws Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Tengu Botnet Enhances IoT Device Resilience
  • Frenos Secures $1.52M to Enhance OT Security Innovations
  • Nimbus Manticore Targets Critical Sectors with New Malware
  • Chinese Firm Allegedly Builds Network for PLA Cyber Ops
  • Microsoft Launches MAI-Cyber-1-Flash for Enhanced Cybersecurity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Tengu Botnet Enhances IoT Device Resilience
  • Frenos Secures $1.52M to Enhance OT Security Innovations
  • Nimbus Manticore Targets Critical Sectors with New Malware
  • Chinese Firm Allegedly Builds Network for PLA Cyber Ops
  • Microsoft Launches MAI-Cyber-1-Flash for Enhanced Cybersecurity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark