hacker-news · Crawled Jul 28, 2026
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
2 IoCs
Read original article ↗
AI Summary
The Tengu botnet, a Mirai-derived malware, targets Linux devices and employs advanced persistence and self-defense mechanisms. It uses a hardware watchdog to reboot compromised devices when its main process is killed, allowing other persistence methods to relaunch it. Tengu supports 25 DDoS methods, can run a SOCKS5 proxy, execute shell commands, and retrieve additional ELF or APK payloads. It communicates with a C2 server at 64.89.163.8 over port 9931 and abuses IPFS for payload delivery.
AI-extracted · verify before operational use