Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process.

If that happens, Tengu’s other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force.

Tengu supports 25 distributed denial-of-service (

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze

Attack Update: Top 5 Attack-IPs auf doode.info – 31.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 23.234.100.38 — 269 requests (recent log) 89.167.35.212 — 240 requests (recent log) 62.60.130.142 — 233 requests (recent

How AI is breaking the British state

How AI is breaking the British state Source: Hacker News