Skip to content

Tengu Botnet Exploits Hardware Watchdog for Recovery After Process Termination

In a nutshell: Tengu leverages the hardware watchdog of Linux devices as a resilience mechanism to restart after process termination by Defender.

The Mirai-derived botnet Tengu features a resilience mechanism that triggers the hardware watchdog of a Linux system to reboot the device when security teams terminate its main process. This gives the botnet a second chance to regain a foothold through alternative persistence mechanisms.

Tengu is a Mirai-derived botnet that employs an unusual tactic to defend itself against removal attempts by security teams. When Defender terminates the botnet’s main process, Tengu manipulates the hardware watchdog of the Linux system to trigger a reboot. This gives the botnet an additional opportunity to re-establish itself through alternative persistence mechanisms.

Nozomi Networks Labs observed the Tengu dropper gaining access via Telnet brute-force attacks on honeypots. The botnet supports 25 different distributed denial-of-service attack methods, combining unsophisticated breach tactics with increased complexity regarding incident response.

For CISOs, this finding means that standard process termination as a response mechanism against Tengu is insufficient. The hardware watchdog technique requires deeper forensic analysis and coordinated measures to block all persistence mechanisms simultaneously. Special attention should be paid to weak Telnet authentication, default credentials, and exposed management interfaces to prevent initial infiltration.


Source: thehackernews.com · Published 28 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: