ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Tengu Mirai-variant abuses Linux watchdog to restart after process kills

Source headline: Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 3 hours ago

Intelligence Summary

A Mirai-derived botnet dubbed Tengu can force rebooting of compromised Linux hosts via the hardware watchdog. When defenders terminate its main process, the watchdog-triggered reboot can help Tengu quickly regain execution. Nozomi Networks Labs reports the dropper reached honeypots using Telnet credential brute forcing. This behavior increases the resilience of the malware’s persistence and complicates remediation. The campaign also supports distributed denial-of-service capabilities, raising availability and disruption risk for affected systems.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#botnet #linux #mirai #telnet-bruteforce #tengu #watchdog-reboot
Original reporting The Hacker News Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
Open original source