Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Read full story on The Hacker News
Share
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
AI disclosure

Summary

A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force. Tengu supports 25 distributed denial-of-service (

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.