Researchers at Nozomi Networks Labs have identified Tengu, a sophisticated Mirai-derived botnet that utilizes hardware watchdogs and multiple persistence mechanisms to maintain control over compromised Linux-based IoT devices.
Key Points
- Tengu uses a hardware watchdog to force device reboots if security defenders terminate its primary malicious process.
- The malware supports 25 distinct DDoS attack methods, SOCKS5 proxy capabilities, and the ability to execute shell commands.
- It targets various architectures including i386, amd64, MIPS, ARM, PowerPC, and m68k, with potential for Android-based device infection.
- Persistence is maintained through fake systemd services, modified init scripts, and by marking its binary files as immutable.
- The botnet overwrites standard reboot and shutdown utilities with "ELFOOD" headers to prevent administrators from safely restarting infected hardware.
- Nozomi Networks Labs recommends disabling Telnet, updating firmware, and segmenting IoT networks to mitigate the risk of Tengu infections.