Skip to content
Tengu Botnet Utilizes Hardware Watchdog to Evade Detection and Removal

Tengu Botnet Utilizes Hardware Watchdog to Evade Detection and Removal

First seen 28 Jul 2026, 21:24 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 29, 2026 at 17:47 UTC
  • Tengu botnet uses hardware watchdogs to erase forensic evidence upon reboot.
  • It targets IoT devices with exposed Telnet services, complicating removal efforts.
  • The malware employs fileless techniques, making detection significantly harder.

The Tengu botnet, a new variant derived from Mirai, has been discovered by Nozomi Networks Labs. It exploits the hardware watchdog feature in IoT devices to erase forensic evidence during reboots triggered by defenders attempting to kill its processes. This malware targets embedded Linux systems, particularly those with exposed Telnet services, and employs advanced evasion techniques, including fileless execution using the Linux memfd_create system call. Tengu's command-and-control communications include both plaintext and encrypted messages, enhancing its resilience against detection. The botnet can facilitate distributed denial-of-service attacks and maintain persistence on compromised devices. Security experts emphasize the need for timely patching and monitoring of IoT devices to mitigate risks. The malware's sophistication marks a significant evolution in IoT threats, making recovery from infections increasingly challenging.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2026-07-28
Tengu botnet disclosed by Nozomi Networks
Nozomi Networks Labs revealed the Tengu botnet, highlighting its use of hardware watchdogs to evade detection.
Techtimes
2026-07-28
Tengu botnet's capabilities detailed
The botnet was found to support DDoS attacks and utilize encrypted C2 communications, enhancing its operational security.
Gbhackers
2026-07-28
Tengu botnet's evasion techniques analyzed
The malware's use of memfd_create for fileless execution was discussed, showcasing its stealthy nature.
Sandfly Security
2026-07-29
Nozomi Networks publishes detailed analysis
A comprehensive analysis of Tengu's architecture and attack methods was published, emphasizing its advanced persistence mechanisms.
Nozomi Networks

More articles in this cluster (10)

Following this threat?

Track Aisuru and Mossad in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed