Tengu Botnet Exploits Hardware Watchdog to Evade Detection and Reboot Devices

Tengu Botnet Exploits Hardware Watchdog to Evade Detection and Reboot Devices

First seen 28 Jul 2026, 21:24 UTC CybersecuritynewsThehackernewsTechtimeswww.nozominetworks.comsandflysecurity.com+1 86% similarity 70.2

Article Content

Browse articles
ThreatCluster

Security researchers have identified the Tengu botnet, a new variant derived from Mirai, which exploits the hardware watchdog feature in IoT devices to erase forensic evidence during cleanup attempts. When defenders attempt to kill its main process, Tengu triggers a forced reboot, wiping volatile memory and allowing the malware to reinstall itself from multiple persistence locations. The botnet primarily targets internet-facing embedded Linux systems, particularly those with exposed Telnet services. Tengu's operational sophistication is notable, utilizing advanced techniques such as the Linux memfd_create system call to run binaries from RAM, leaving no trace on disk. This makes traditional detection methods ineffective. The botnet supports distributed denial-of-service (DDoS) attacks and poses a significant threat to compromised devices. The discovery was made by Nozomi Networks Labs, who observed Tengu's behavior through honeypots.

Key Points: • Tengu botnet uses hardware watchdog to erase evidence during cleanup attempts. • The botnet targets IoT devices, particularly those with exposed Telnet services. • Advanced techniques like memfd_create allow Tengu to evade traditional detection methods.

ThreatCluster AI How this analysis works

Timeline

2026-07-28
Tengu botnet disclosed
Nozomi Networks Labs revealed the Tengu botnet's unique evasion techniques, including hardware watchdog exploitation.
Techtimes
2026-07-28
Tengu's attack method detailed
The botnet triggers a reboot to erase forensic evidence when defenders kill its process, complicating cleanup efforts.
Thehackernews
2026-07-28
Tengu targets IoT devices
The botnet is particularly effective against internet-facing embedded Linux systems with exposed remote admin services.
Cybersecuritynews

Community

Browse all →