Bottom line: Tengu combines hardware watchdog abuse with multiple persistence mechanisms into a self-protection system that circumvents Defender termination through forced reboots of compromised Linux devices.
On 27 July 2026, Nozomi Networks Labs analysed the Tengu botnet, a Mirai variant that abuses the hardware watchdog of compromised Linux devices to automatically secure malware execution. The botnet combines multiple persistence mechanisms and offers 25 DDoS attack methods.
Tengu hides a monitoring process under the name kworker/0:0, which activates the hardware watchdog of the device and configures it with a time window of approximately 30 seconds. As long as the malware main process is running, this watchdog process continuously sends signals to the watchdog. If a Defender terminates the main process, these signals cease and the watchdog forces a device reboot – whereupon the other persistence mechanisms reload the malware.
In addition to this watchdog mechanism, the researchers describe a decoupled monitoring routine that checks the main process every 60 seconds and restarts the binary if necessary. Tengu also creates fake systemd services, augments init and RC scripts, modifies shell startup files, marks the binary as immutable, and uses cron-based persistence. Nozomi highlights that this combination of persistence and self-protection functions is unusual among Mirai variants. The malware also carries hardcoded reboot and shutdown commands, whose ELF headers it overwrites with the string ELFOOD to disrupt regular security commands.
Tengu spreads via Telnet brute-force attacks and supports 25 different DDoS attack methods. The malware operates SOCKS5 proxies, executes shell commands, and collects system and network data. It can update itself and download additional malware in ELF or Android APK format. Nozomi identified architecture-specific variants for i386, amd64, MIPS, ARM, PowerPC, and m68k, indicating a broad target spectrum.
Communication with the command server takes place over TCP port 9931 to IP 64.89.163.8. Registration and status reports are unencrypted, while commands and updates use an encryption scheme based on ChaCha20/Poly1305. Tengu can retrieve a payload from an InterPlanetary File System gateway (IPFS) on the same server, validate the result, and then execute or install it. According to Nozomi’s assessment, the APK path is particularly aimed at insufficiently secured Android TV boxes and similar devices. The report names neither specific manufacturers, device models, operators, nor actual infection numbers or documented DDoS victims – thus demonstrating the malware’s capabilities without making statements about its actual distribution.
Source: www.it-daily.net · Published 30 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.