Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process.

If that happens, Tengu’s other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force.

Tengu supports 25 distributed denial-of-service (

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Clinical failure rates over the decades: yikes

Clinical failure rates over the decades: yikes Source: Hacker News

Google AI Mode shows same products 21.6% more expensive than traditional search

Google AI Mode shows same products 21.6% more expensive than traditional search Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 21.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 74.7.227.165 — 1333 requests (recent log) 89.167.35.212 — 1131 requests (recent log) 34.73.198.38 — 660 requests (recent