ThreatCluster

Tengu Mirai: New Linux Botnet Threat Emerges

First seen 7 Sep 2026, 20:33 UTC GbhackersCybersecuritynews 49

Article Content

Browse articles
ThreatCluster

A new Linux malware named Tengu has been identified, combining Mirai-style botnet techniques with advanced persistence and DDoS capabilities. This 32-bit ELF malware disguises itself as a Linux kernel worker process and targets servers, embedded devices, and IoT systems. Tengu's features include SSH probing and proxy capabilities, making it a versatile threat. The malware is designed to remain hidden and can generate significant traffic floods against selected targets. Its stealthy nature and broad attack vector increase the risk for various Linux environments. Currently, there are no specific CVEs or patches mentioned for this malware, indicating a potential gap in defenses. Security professionals are advised to monitor their systems for unusual activity related to this threat.

Key Points: • Tengu malware mimics Linux kernel processes to evade detection. • Targets include servers, embedded devices, and IoT systems. • Capable of launching DDoS attacks and SSH probing.

Ask AI about this cluster

Timeline

2026-09-07
Tengu malware identified
Security researchers reported the discovery of Tengu, a new Linux bot that combines Mirai techniques with advanced persistence.
Gbhackers
2026-09-07
Tengu's capabilities detailed
The malware's ability to disguise itself as a kernel worker and perform DDoS attacks was highlighted in multiple reports.
Cybersecuritynews