BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Tengu Botnet Uses Watchdog to Reboot Linux Devices

New Mirai-derived Tengu botnet exploits Linux hardware watchdog to reboot devices when main process killed

  • Security researchers at Nozomi Networks Labs discovered Tengu, a new Mirai-derived botnet that exploits Linux hardware watchdogs to reboot compromised devices when its main process is killed.
  • Once rebooted, Tengu’s other persistence mechanisms can relaunch the malware, making it highly resilient to standard disruption tactics.
  • The botnet supports 25 DDoS methods, runs a SOCKS5 proxy, executes shell commands, and can download additional ELF or Android payloads.

Researchers at Nozomi Networks Labs published their analysis of a new Mirai-derived botnet called Tengu on July 27, 2026, after observing it target Linux devices via Telnet credential brute force.

- Advertisement -

The malware stands out for its sophisticated self-defense mechanisms, including a hardware watchdog abuse that triggers a reboot when defenders kill its main process.

Tengu forks a detached guardian process that checks the principal malware every 60 seconds and relaunches it if it stops.

A second mechanism uses the device’s hardware watchdog, arming it with a 30-second timeout and sending keepalive signals only while the main process lives.

Kill the main process, and the watchdog triggers a reboot, allowing Tengu’s other persistence methods to try again.

- Advertisement -

The botnet also overwrites the ELF headers of system reboot and shutdown utilities with the string “ELFOOD,” interfering with normal shutdown commands.

Tengu includes a hardcoded command-and-control server at 64[.]89.163.8 over TCP port 9931, using plaintext for registration but a custom ChaCha20/Poly1305 scheme for server commands.

The malware can also retrieve content from an InterPlanetary File System (IPFS) gateway on the same server, validating it as an ELF or APK before execution.

Nozomi assessed the APK path likely targets Android TV boxes, according to its report, but did not document confirmed victims.

URLhaus independently recorded 17 malware URLs at the same IP address beginning June 17, 2026, including files tagged as Mirai and an APK, though it does not identify them as Tengu.

The researchers at Nozomi recommend removing internet exposure for Telnet, replacing default credentials, updating firmware, and segmenting IoT networks.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

OpenSSL DTLS bug leaks heap memory, crashes apps

OpenSSL's CVE-2026-84782 DTLS flaw can leak heap memory across a connection or crash programs.Fixes...

Tesla signs $30B unused credit lines for the AI and robotics

Tesla signed $30 billion in unused senior unsecured bank facilities, including a $20 billion...

New Spectre-v2 CPU Variant ‘BTR’ Hits JIT Engines

Academics disclosed a new Spectre-v2 CPU vulnerability variant, Branch Target Reuse (BTR), affecting JIT...

Cboe, S&P Extend Deal, Eye Tokenized Options

Cboe Global Markets and S&P Dow Jones Indices extended their exclusive licensing agreement through...

OpenAI launches Dots assistant, seeks $30B funding

OpenAI launched "Dots," a persistent virtual assistant operating computers and debugging software autonomously.The company...

Must Read

Top 5 Testing Tools For Blockchain Applications in 2022

Blockchain apps have been adopted popularly by some prominent industries due to its being a decentralized-designed technology. Furthermore, these apps eliminate the risks that...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading