The record
Written from the 1 report below. Nothing here is unsourced.
- Nozomi Networks Labs has identified a new Mirai-derived botnet called Tengu that targets Linux devices, spreading via Telnet credential brute force.
- Its standout feature is self-defense: a guardian process relaunches the malware every 60 seconds if killed, and it can abuse the device's hardware watchdog to force a reboot when its process is stopped, giving its persistence mechanisms another chance to reactivate.
- Tengu supports 25 DDoS methods, can run a SOCKS5 proxy, execute commands, and download additional payloads, including Android APKs that likely target poorly secured Android TV boxes.
- The report describes capabilities but does not document infection counts, victims, or operators, and defenders are advised to close Telnet exposure, change default credentials, and update firmware.
What to watch next
- Whether Nozomi provides additional details on Tengu's observed scale, infrastructure status, and sample linkage in response to inquiries
- Whether the C2 server at 64[.]89.163.8 and its IPFS gateway are confirmed active or issuing commands
- Any confirmed Android victims or real-world DDoS attacks attributed to Tengu
Coverage1
1 report
English national1
All filed from India
Named India · Mirai · Nozomi Networks Labs · Tengu Botnet · URLhaus
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
