AUTO-UPDATED

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Researchers at Nozomi Networks Labs have identified Tengu, a sophisticated Mirai-derived botnet that utilizes hardware watchdogs and multiple persistence mechanisms to maintain control over compromised Linux-based IoT devices.

Key Points

  • Tengu uses a hardware watchdog to force device reboots if security defenders terminate its primary malicious process.
  • The malware supports 25 distinct DDoS attack methods, SOCKS5 proxy capabilities, and the ability to execute shell commands.
  • It targets various architectures including i386, amd64, MIPS, ARM, PowerPC, and m68k, with potential for Android-based device infection.
  • Persistence is maintained through fake systemd services, modified init scripts, and by marking its binary files as immutable.
  • The botnet overwrites standard reboot and shutdown utilities with "ELFOOD" headers to prevent administrators from safely restarting infected hardware.
  • Nozomi Networks Labs recommends disabling Telnet, updating firmware, and segmenting IoT networks to mitigate the risk of Tengu infections.

Why it Matters

This botnet represents an evolution in Mirai-based threats by incorporating advanced self-defense and persistence techniques that make standard remediation efforts significantly more difficult. Organizations must prioritize securing IoT infrastructure, as these devices are increasingly targeted for use in large-scale distributed denial-of-service attacks.
Internet Published by info@thehackernews.com (The Hacker News)
Read original