hacker-news · Crawled Jul 28, 2026

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

2 IoCs
Read original article ↗

AI Summary

The Tengu botnet, a Mirai-derived malware, targets Linux devices and employs advanced persistence and self-defense mechanisms. It uses a hardware watchdog to reboot compromised devices when its main process is killed, allowing other persistence methods to relaunch it. Tengu supports 25 DDoS methods, can run a SOCKS5 proxy, execute shell commands, and retrieve additional ELF or APK payloads. It communicates with a C2 server at 64.89.163.8 over port 9931 and abuses IPFS for payload delivery.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
IP 64[.]89[.]163[.]8 Details →
Domain 64[.]89[.]163[.]8 Details →