Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
Summary
A new Mirai-derived botnet named Tengu has been observed utilizing a Linux device's hardware watchdog timer to ensure its persistence. When defenders attempt to terminate the botnet's main process, Tengu can trigger a reboot, allowing its other mechanisms to relaunch the malicious software. The botnet initially infects devices through Telnet credential brute-force attacks and supports various DDoS attack vectors.
IFF Assessment
This article describes a new botnet with advanced persistence mechanisms, posing an increased threat to network defenders.
Defender Context
Defenders need to be aware of the Tengu botnet's novel persistence technique, which uses hardware watchdog timers to circumvent process termination. This highlights the ongoing evolution of malware to evade detection and removal, requiring robust endpoint monitoring and incident response strategies.