Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI-Assisted Research Finds Linux Kernel Zero-Day for Root Escalation
July 28, 2026
GhostNet: Chinese Cyber Espionage Network Linked to PLA Attacks
July 28, 2026
Tengu Mirai Botnet Reboots IoT Devices, Resists Termination Attempts
July 28, 2026
Home/Threats/Tengu Mirai Botnet Reboots IoT Devices, Resists Termination Attempts
Threats

Tengu Mirai Botnet Reboots IoT Devices, Resists Termination Attempts

Key Takeaways Tengu is a new Mirai-based botnet targeting internet-facing embedded Linux IoT devices. It possesses advanced anti-analysis and persistence mechanisms, including a unique ability to...

Emy Elsamnoudy
Emy Elsamnoudy
July 28, 2026 3 Min Read
2 0

Key Takeaways

  • Tengu is a new Mirai-based botnet targeting internet-facing embedded Linux IoT devices.
  • It possesses advanced anti-analysis and persistence mechanisms, including a unique ability to reboot infected devices upon detecting termination attempts.
  • The botnet primarily exploits exposed remote administration services like Telnet and weak credentials.
  • Affected devices include routers, cameras, and DVRs, which often run outdated firmware or use default passwords.
  • Effective mitigation requires proactive security measures beyond simple reboots, focusing on reducing exposure, strong authentication, and continuous monitoring.

Tengu Botnet: A Resilient IoT Threat

A sophisticated new variant of the Mirai botnet, dubbed Tengu, has emerged, demonstrating enhanced capabilities to maintain control over compromised Internet of Things (IoT) devices. This botnet specifically targets embedded Linux systems accessible from the internet, particularly those with exposed remote administration services such as Telnet. Once a device is infected, Tengu makes removal significantly more challenging, transforming standard cleanup efforts into complex operational hurdles.

Table Of Content

  • Key Takeaways
  • Tengu Botnet: A Resilient IoT Threat
  • Advanced Anti-Tampering and Persistence
  • Vulnerability Through Exposure

Tengu largely follows the established Mirai methodology of exploiting poorly secured connected devices, but it introduces robust mechanisms to resist removal. Devices like routers, security cameras, and digital video recorders (DVRs) are prime targets due to their common exposure online, often running outdated firmware or relying on factory-default credentials. The persistent threat of Mirai botnets exploiting vulnerabilities in everyday network equipment has been well-documented, and Tengu elevates this risk.

Security researchers at Nozomi said in a report that they identified a distinctive feature of Tengu: its capacity to reboot an infected IoT device when attempts are made to terminate its malicious processes. This behavior, detailed in a technical analysis, is designed to ensure persistence and maintain unauthorized access even after detection.

This self-rebooting capability poses a significant challenge for incident response teams. While a reboot might temporarily disrupt botnet operations like surveillance or malicious communications, it often gives administrators a false sense of security that the device has been cleansed. Critically, it can also lead to the loss of volatile forensic evidence if not collected before the reboot. This underscores that merely cycling power on and off is insufficient for effectively neutralizing IoT botnet infections.

Advanced Anti-Tampering and Persistence

Tengu employs sophisticated methods to monitor its operational integrity. It continuously checks its own running state and detects any alterations to its code. By reading memory-mapping information from the Linux proc filesystem, the malware establishes a baseline SHA-256 hash for a portion of its code. This hash is then constantly compared against the current state to identify any unauthorized modifications. Furthermore, Tengu actively scans for writable memory mappings, which could indicate attempts at analysis or modification by security professionals.

Upon detecting an attempt to stop or modify its processes, the botnet initiates a reboot of the compromised device. This action serves multiple purposes: it erases temporary traces of the failed removal attempt, disrupts the cleaning process, and forces incident responders to contend with a restarted system, potentially losing valuable in-memory evidence. The botnet’s persistence mechanisms further complicate remediation efforts. Defenders must meticulously examine systemd services, init scripts, shell startup files, and cron job configurations, as other Linux botnets have historically leveraged these areas for maintaining access post-compromise.

Vulnerability Through Exposure

Tengu primarily capitalizes on the widespread issue of internet-exposed IoT and embedded Linux devices, particularly those with Telnet or other administrative services unnecessarily accessible from outside the local network. Attackers exploit poor credential management, often leveraging default or weak passwords, to gain initial access. Older network equipment, such as web cameras and DVRs with known vulnerable services, remains particularly susceptible to such attacks.

The broader implications of large IoT botnets, including their use for Distributed Denial of Service (DDoS) attacks or as proxy networks, are a growing concern. The <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b40f8ac4-6397-47d8-a725-0edc6b7efdef/New-Tengu-Mirai-Botnet-Reboots-Your-IoT-Device-When-You-Try-to-Kill-It.pdf?AWSAccessKeyId=ASIA2F3EMEYEQN3TSARN&Signature=sqvTpVIaJJCMjBxsNw%2BqTWuQyTs%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEJn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDP55Giv1GqF3FuXwyHMmuMK52aW16lAf3q1nykAu95WQIhAMUHDYxJPbCsgioU%2BrwEuYQt89%2BSFfOo6ir6nOc9tjMlKvMECGIQARoMNjk5NzUzMzA5NzA1IgxarF%2BtgjLobwKZocwq0ARdBd5V84iTb2NrFdwLg0WtwaVqC6k9yrS74DKdnFcii%2Bnrc8gyctZ9HId%2FoEKH%2B94x33YWBlVHkeOW1DnwCoZuOL1UKSFyKa%2FFFcOk0h3HC82z2BwLYs52lopkHyWeWSxpFjD61msmGP62nbGkkWZqhne1yaXGwjiKryB4Ws6%2BHY5tuZ5FDdZd%2B6GM2tKIsb3Y29zXne9RSPGLfj0Fhmiwq%2F0GGANEWH%2BCfIQ0focWoX9uMskkiy%2F3rgg8fxcfmrN9R63j9%2FTHKLoRe92tnl5SJWLqDBkGIlf65eQN4wA6lWd1%2FXmEXfJtFVgOUmucJ6dQ6K1XvDjaxlm%2BGc2KpBSru8ljYNwrOxbAdutlMAaBTOFmr2yUc2OYOWSSK4CY%2FogIkOwfvjxW1%2FxozSqd106XpOqQU6wYqtFsEQkRIthQhWpq1B%2BW0Qr0KC7UZNEKep9wBNAgcfRFkSxdWeyr7N%2Bpu6vvajKP1UId9NM%2Bk8abPsJbxXeNcKxdpGazUbiyFn%2BOH6zO4E7KYEkKTel5RIUsOTpx9Ons8PvtkKbS2YjGLD5SQ5K8Jlu1DXwg4CEZH3cct3yDG7VXucJcVIDIrplbWmFJQq0LZJzl3qaxXGf19tt%2Fsgbc42SURzJvUVzpx9uWonfZlazKYVI14V7xoPl%2FgIcQZ%2BIdIdKM0WGvvBh6

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical LegacyHive Exploits Bypass Windows Security, Even With July 2026 Patches

Next Post

GhostNet: Chinese Cyber Espionage Network Linked to PLA Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Arista VeloCloud Orchestrator Zero-Day Actively Exploited
July 28, 2026
Dysphoria Botnet Infects 200,000 IoT Devices, Hides C2 on Blockchain
July 28, 2026
Scammers Impersonate ShinyHunters, Blackmail Breach Victims with Fake Webcam Videos
July 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us