Thehackernews Tengu Botnet Utilizes Hardware Watchdog to Evade Detection and Removal
Article Content
- •Tengu botnet uses hardware watchdogs to erase forensic evidence upon reboot.
- •It targets IoT devices with exposed Telnet services, complicating removal efforts.
- •The malware employs fileless techniques, making detection significantly harder.
The Tengu botnet, a new variant derived from Mirai, has been discovered by Nozomi Networks Labs. It exploits the hardware watchdog feature in IoT devices to erase forensic evidence during reboots triggered by defenders attempting to kill its processes. This malware targets embedded Linux systems, particularly those with exposed Telnet services, and employs advanced evasion techniques, including fileless execution using the Linux memfd_create system call. Tengu's command-and-control communications include both plaintext and encrypted messages, enhancing its resilience against detection. The botnet can facilitate distributed denial-of-service attacks and maintain persistence on compromised devices. Security experts emphasize the need for timely patching and monitoring of IoT devices to mitigate risks. The malware's sophistication marks a significant evolution in IoT threats, making recovery from infections increasingly challenging.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track Aisuru and Mossad in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Cyber Threats Loom Over US Elections Amid Record DDoS Attacks As the US prepares for the presidential election, cybersecurity experts warn of potential disruptions from hackers. Recent record-breaking DDoS attacks, including a 31.4 terabit-per-second assault linked to the Aisuru botnet, raise concerns about election infrastructure. Experts emphasize that even smaller, less…
DDoS Attacks Intensify Despite Decrease in Frequency: Link11 Report Link11's European Cyber Report for the first half of 2026 reveals a 42% decrease in DDoS attacks on European organizations, yet the intensity of these attacks has reached unprecedented levels. The highest recorded bandwidth attack peaked at 2.3 Tbit/s, an 85% increase from the previous year. Packet rates also surged…