importantSYS.SOURCE: The Hacker News• 2026-07-28T20:31:33+05:30
Tengu Botnet Exploits Linux Hardware Watchdogs for Persistence After Process Termination
The Tengu botnet uses Linux hardware watchdogs to reboot devices when its processes are killed, ensuring persistence. It is a Mirai-derived botnet with DDoS capabilities, SOCKS5 proxy support, and advanced self-defense mechanisms.
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process.
If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force.
Tengu supports 25 distributed denial-of-service (
*** END OF TRANSMISSION ***