Tengu Mirai Botnet Reboots IoT Devices, Resists Termination Attempts
Key Takeaways Tengu is a new Mirai-based botnet targeting internet-facing embedded Linux IoT devices. It possesses advanced anti-analysis and persistence mechanisms, including a unique ability to...
Key Takeaways
- Tengu is a new Mirai-based botnet targeting internet-facing embedded Linux IoT devices.
- It possesses advanced anti-analysis and persistence mechanisms, including a unique ability to reboot infected devices upon detecting termination attempts.
- The botnet primarily exploits exposed remote administration services like Telnet and weak credentials.
- Affected devices include routers, cameras, and DVRs, which often run outdated firmware or use default passwords.
- Effective mitigation requires proactive security measures beyond simple reboots, focusing on reducing exposure, strong authentication, and continuous monitoring.
Tengu Botnet: A Resilient IoT Threat
A sophisticated new variant of the Mirai botnet, dubbed Tengu, has emerged, demonstrating enhanced capabilities to maintain control over compromised Internet of Things (IoT) devices. This botnet specifically targets embedded Linux systems accessible from the internet, particularly those with exposed remote administration services such as Telnet. Once a device is infected, Tengu makes removal significantly more challenging, transforming standard cleanup efforts into complex operational hurdles.
Table Of Content
Tengu largely follows the established Mirai methodology of exploiting poorly secured connected devices, but it introduces robust mechanisms to resist removal. Devices like routers, security cameras, and digital video recorders (DVRs) are prime targets due to their common exposure online, often running outdated firmware or relying on factory-default credentials. The persistent threat of Mirai botnets exploiting vulnerabilities in everyday network equipment has been well-documented, and Tengu elevates this risk.
Security researchers at Nozomi said in a report that they identified a distinctive feature of Tengu: its capacity to reboot an infected IoT device when attempts are made to terminate its malicious processes. This behavior, detailed in a technical analysis, is designed to ensure persistence and maintain unauthorized access even after detection.
This self-rebooting capability poses a significant challenge for incident response teams. While a reboot might temporarily disrupt botnet operations like surveillance or malicious communications, it often gives administrators a false sense of security that the device has been cleansed. Critically, it can also lead to the loss of volatile forensic evidence if not collected before the reboot. This underscores that merely cycling power on and off is insufficient for effectively neutralizing IoT botnet infections.
Advanced Anti-Tampering and Persistence
Tengu employs sophisticated methods to monitor its operational integrity. It continuously checks its own running state and detects any alterations to its code. By reading memory-mapping information from the Linux proc filesystem, the malware establishes a baseline SHA-256 hash for a portion of its code. This hash is then constantly compared against the current state to identify any unauthorized modifications. Furthermore, Tengu actively scans for writable memory mappings, which could indicate attempts at analysis or modification by security professionals.
Upon detecting an attempt to stop or modify its processes, the botnet initiates a reboot of the compromised device. This action serves multiple purposes: it erases temporary traces of the failed removal attempt, disrupts the cleaning process, and forces incident responders to contend with a restarted system, potentially losing valuable in-memory evidence. The botnet’s persistence mechanisms further complicate remediation efforts. Defenders must meticulously examine systemd services, init scripts, shell startup files, and cron job configurations, as other Linux botnets have historically leveraged these areas for maintaining access post-compromise.
Vulnerability Through Exposure
Tengu primarily capitalizes on the widespread issue of internet-exposed IoT and embedded Linux devices, particularly those with Telnet or other administrative services unnecessarily accessible from outside the local network. Attackers exploit poor credential management, often leveraging default or weak passwords, to gain initial access. Older network equipment, such as web cameras and DVRs with known vulnerable services, remains particularly susceptible to such attacks.
The broader implications of large IoT botnets, including their use for Distributed Denial of Service (DDoS) attacks or as proxy networks, are a growing concern. The <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b40f8ac4-6397-47d8-a725-0edc6b7efdef/New-Tengu-Mirai-Botnet-Reboots-Your-IoT-Device-When-You-Try-to-Kill-It.pdf?AWSAccessKeyId=ASIA2F3EMEYEQN3TSARN&Signature=sqvTpVIaJJCMjBxsNw%2BqTWuQyTs%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEJn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDP55Giv1GqF3FuXwyHMmuMK52aW16lAf3q1nykAu95WQIhAMUHDYxJPbCsgioU%2BrwEuYQt89%2BSFfOo6ir6nOc9tjMlKvMECGIQARoMNjk5NzUzMzA5NzA1IgxarF%2BtgjLobwKZocwq0ARdBd5V84iTb2NrFdwLg0WtwaVqC6k9yrS74DKdnFcii%2Bnrc8gyctZ9HId%2FoEKH%2B94x33YWBlVHkeOW1DnwCoZuOL1UKSFyKa%2FFFcOk0h3HC82z2BwLYs52lopkHyWeWSxpFjD61msmGP62nbGkkWZqhne1yaXGwjiKryB4Ws6%2BHY5tuZ5FDdZd%2B6GM2tKIsb3Y29zXne9RSPGLfj0Fhmiwq%2F0GGANEWH%2BCfIQ0focWoX9uMskkiy%2F3rgg8fxcfmrN9R63j9%2FTHKLoRe92tnl5SJWLqDBkGIlf65eQN4wA6lWd1%2FXmEXfJtFVgOUmucJ6dQ6K1XvDjaxlm%2BGc2KpBSru8ljYNwrOxbAdutlMAaBTOFmr2yUc2OYOWSSK4CY%2FogIkOwfvjxW1%2FxozSqd106XpOqQU6wYqtFsEQkRIthQhWpq1B%2BW0Qr0KC7UZNEKep9wBNAgcfRFkSxdWeyr7N%2Bpu6vvajKP1UId9NM%2Bk8abPsJbxXeNcKxdpGazUbiyFn%2BOH6zO4E7KYEkKTel5RIUsOTpx9Ons8PvtkKbS2YjGLD5SQ5K8Jlu1DXwg4CEZH3cct3yDG7VXucJcVIDIrplbWmFJQq0LZJzl3qaxXGf19tt%2Fsgbc42SURzJvUVzpx9uWonfZlazKYVI14V7xoPl%2FgIcQZ%2BIdIdKM0WGvvBh6
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.