Thehackernews
Tengu Botnet Utilizes Hardware Watchdog to Evade Detection and Removal
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Tengu botnet, a new variant derived from Mirai, has been discovered by Nozomi Networks Labs. It exploits the hardware watchdog feature in IoT devices to erase forensic evidence during reboots triggered by defenders attempting to kill its processes. This malware targets embedded Linux systems, particularly those with exposed Telnet services, and employs advanced evasion techniques, including fileless execution using the Linux memfd_create system call. Tengu's command-and-control communications include both plaintext and encrypted messages, enhancing its resilience against detection. The botnet can facilitate distributed denial-of-service attacks and maintain persistence on compromised devices. Security experts emphasize the need for timely patching and monitoring of IoT devices to mitigate risks. The malware's sophistication marks a significant evolution in IoT threats, making recovery from infections increasingly challenging.
Key Points: • Tengu botnet uses hardware watchdogs to erase forensic evidence upon reboot. • It targets IoT devices with exposed Telnet services, complicating removal efforts. • The malware employs fileless techniques, making detection significantly harder.