Tengu is a Mirai-derived botnet targeting Linux-based IoT, embedded, and other internet-exposed devices. It has been observed propagating through Telnet credential brute forcing. The malware supports 25 distributed-denial-of-service attack methods, SOCKS5 proxying, shell-command execution, collection of host and network configuration data, self-updates, and retrieval and execution of additional ELF payloads; it can also retrieve APK payloads, although confirmed Android compromises have not been established.
Tengu is distinguished from typical Mirai variants by extensive persistence and self-defense mechanisms. It can create Linux startup persistence through service and initialization mechanisms, restart its main process through a guardian component, and mark its binary immutable. It abuses the Linux hardware watchdog so that termination of its main process can cause a forced device reboot, after which its persistence components can restore the botnet. Tengu also interferes with ordinary shutdown and reboot actions by corrupting relevant system utilities, kills competing malware processes, masquerades as legitimate system processes, and incorporates anti-debugging and anti-analysis checks. Samples have been identified for several Linux architectures, including x86, x86-64, ARM, MIPS, PowerPC, and m68k. No threat actor, victim set, or infection scale has been conclusively attributed to Tengu.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
"[Tengu] attempts to survive reboots through ... scheduled tasks..."
Besides persistence through systemd and init.d... Tengu tries to use cron, the tool for scheduling recurring tasks, though Nozomi found this method doesn’t work as intended.
...добавляет init- и rc-скрипты, меняет стартовые файлы оболочки...
"[Tengu] attempts to survive reboots through ... scheduled tasks..."
Besides persistence through systemd and init.d... Tengu tries to use cron, the tool for scheduling recurring tasks, though Nozomi found this method doesn’t work as intended.
Tengu, observed by Nozomi Networks Labs, spreads through Telnet credential brute-forcing
Также для закрепления в системе Tengu создает фиктивный systemd...
"[Tengu] attempts to survive reboots through ... SysV and OpenWrt startup scripts..."
"[Tengu] attempts to survive reboots through ... local startup files."
Its unique persistence strategy involves a guardian process that monitors the main malware and relaunches it if stopped. Critically, it can also leverage the hardware watchdog timer; if the main process is killed, the watchdog is left unfed, causing a device reboot, which then allows Tengu's other persistence methods to reactivate.
...добавляет init- и rc-скрипты, меняет стартовые файлы оболочки...
"[Tengu] attempts to survive reboots through ... scheduled tasks..."
Besides persistence through systemd and init.d... Tengu tries to use cron, the tool for scheduling recurring tasks, though Nozomi found this method doesn’t work as intended.
Tengu, observed by Nozomi Networks Labs, spreads through Telnet credential brute-forcing
Также для закрепления в системе Tengu создает фиктивный systemd...
"[Tengu] attempts to survive reboots through ... SysV and OpenWrt startup scripts..."
"[Tengu] attempts to survive reboots through ... local startup files."
Its unique persistence strategy involves a guardian process that monitors the main malware and relaunches it if stopped. Critically, it can also leverage the hardware watchdog timer; if the main process is killed, the watchdog is left unfed, causing a device reboot, which then allows Tengu's other persistence methods to reactivate.
To reduce the chance of detection, Tengu decrypts its strings only during execution...
...один из компонентов Tengu создает отдельный фоновый процесс, который маскируется под системный поток [kworker/0:0]...
"Tengu replaces its visible process name with a randomized kernel-worker-style label, making it resemble a Linux kernel worker in ordinary process listings."
Tengu, observed by Nozomi Networks Labs, spreads through Telnet credential brute-forcing
"It can gather basic host and network details..."
Эта малварь поддерживает 25 видов DDoS-атак, может развертывать SOCKS5-прокси, выполнять шелл-команды, собирать информацию о системе и сети...
Another process repeatedly scans running processes and terminates competing botnets.
Также обнаружилось, что Tengu мог получать идентификаторы дополнительных файлов с управляющего сервера злоумышленников...
"[Tengu can] build authenticated HTTP CONNECT and SOCKS5 proxy functions" and "infected hosts can also be used to relay traffic."
“With data secured, the attackers deploy the encryptor across as many systems as possible.”
Если малварь обнаружили, и ее основной процесс принудительно завершили, [kworker/0:0] перестает подавать сигналы. В результате сторожевой таймер считает, что устройство зависло, и осуществляет жесткую перезагрузку... Одновременно с этим Tengu мешает администраторам штатно перезагрузить или выключить зараженное устройство.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hands-on-keyboard ransomware-as-a-service operation employing double extortion through data theft and encryption.
A 32-bit Linux ELF bot that masquerades as a kernel worker process, reduces its likelihood of out-of-memory termination, suppresses standard streams, and establishes persistence through systemd, SysV/OpenWrt scripts, scheduled tasks, and startup files. It supports raw and socket-based UDP floods, HTTP GET/POST/HEAD request floods, SSH banner/key-exchange activity, and authenticated HTTP CONNECT/SOCKS5 proxying. Initial access and direct code lineage to Mirai are unconfirmed.
Mentioned as a prior Japanese-themed ransomware group for comparison/background.
Mirai-based IoT malware that uses Telnet brute-force to compromise IoT devices and supports DoS attacks, persistence, command execution, payload download, metadata theft, and proxying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.