Tengu Botnet Utilizes Hardware Watchdog to Evade Detection and Removal

Tengu Botnet Utilizes Hardware Watchdog to Evade Detection and Removal

First seen 28 Jul 2026, 21:24 UTC CybersecuritynewsGbhackersThehackernewsTechtimesFeeds2.Feedburner+5 87% similarity 70.2

Article Content

Browse articles
ThreatCluster

The Tengu botnet, a new variant derived from Mirai, has been discovered by Nozomi Networks Labs. It exploits the hardware watchdog feature in IoT devices to erase forensic evidence during reboots triggered by defenders attempting to kill its processes. This malware targets embedded Linux systems, particularly those with exposed Telnet services, and employs advanced evasion techniques, including fileless execution using the Linux memfd_create system call. Tengu's command-and-control communications include both plaintext and encrypted messages, enhancing its resilience against detection. The botnet can facilitate distributed denial-of-service attacks and maintain persistence on compromised devices. Security experts emphasize the need for timely patching and monitoring of IoT devices to mitigate risks. The malware's sophistication marks a significant evolution in IoT threats, making recovery from infections increasingly challenging.

Key Points: • Tengu botnet uses hardware watchdogs to erase forensic evidence upon reboot. • It targets IoT devices with exposed Telnet services, complicating removal efforts. • The malware employs fileless techniques, making detection significantly harder.

ThreatCluster AI How this analysis works

Timeline

2026-07-28
Tengu botnet disclosed by Nozomi Networks
Nozomi Networks Labs revealed the Tengu botnet, highlighting its use of hardware watchdogs to evade detection.
Techtimes
2026-07-28
Tengu botnet's capabilities detailed
The botnet was found to support DDoS attacks and utilize encrypted C2 communications, enhancing its operational security.
Gbhackers
2026-07-28
Tengu botnet's evasion techniques analyzed
The malware's use of memfd_create for fileless execution was discussed, showcasing its stealthy nature.
Sandfly Security
2026-07-29
Nozomi Networks publishes detailed analysis
A comprehensive analysis of Tengu's architecture and attack methods was published, emphasizing its advanced persistence mechanisms.
Nozomi Networks

Community

Browse all →

Tracked Entities in This Story