ShellCodeX Intelligence Brief
HIGH
Cybersecurity
Tengu Mirai-variant abuses Linux watchdog to restart after process kills
Source headline: Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
Threat level
High
Signal strength
75/100
Source confidence
1 source
Published
3 hours ago
Intelligence Summary
A Mirai-derived botnet dubbed Tengu can force rebooting of compromised Linux hosts via the hardware watchdog. When defenders terminate its main process, the watchdog-triggered reboot can help Tengu quickly regain execution. Nozomi Networks Labs reports the dropper reached honeypots using Telnet credential brute forcing. This behavior increases the resilience of the malware’s persistence and complicates remediation. The campaign also supports distributed denial-of-service capabilities, raising availability and disruption risk for affected systems.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
The Hacker News
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
Open original source