Thehackernews
Tengu Botnet Exploits Hardware Watchdog to Evade Detection and Reboot Devices
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Security researchers have identified the Tengu botnet, a new variant derived from Mirai, which exploits the hardware watchdog feature in IoT devices to erase forensic evidence during cleanup attempts. When defenders attempt to kill its main process, Tengu triggers a forced reboot, wiping volatile memory and allowing the malware to reinstall itself from multiple persistence locations. The botnet primarily targets internet-facing embedded Linux systems, particularly those with exposed Telnet services. Tengu's operational sophistication is notable, utilizing advanced techniques such as the Linux memfd_create system call to run binaries from RAM, leaving no trace on disk. This makes traditional detection methods ineffective. The botnet supports distributed denial-of-service (DDoS) attacks and poses a significant threat to compromised devices. The discovery was made by Nozomi Networks Labs, who observed Tengu's behavior through honeypots.
Key Points: • Tengu botnet uses hardware watchdog to erase evidence during cleanup attempts. • The botnet targets IoT devices, particularly those with exposed Telnet services. • Advanced techniques like memfd_create allow Tengu to evade traditional detection methods.