Researchers reported that Tengu, a modernized Mirai-derived malware family, is compromising internet-facing IoT and embedded Linux devices through Telnet brute force and deploying architecture-specific binaries via a shell-script dropper. The malware communicates with command-and-control infrastructure including 64[.]89.163.8:9931, uses plaintext registration and heartbeat traffic, and encrypts server-to-bot commands and updates with a ChaCha20/Poly1305-like AEAD scheme. Beyond traditional botnet activity, Tengu supports 25 attack methods covering volumetric and protocol-specific floods against services such as HTTP, DNS, NTP, SNMP, SIP, SSH, SMTP, FTP, game servers, and Minecraft, while also enabling proxying, payload delivery, and reconnaissance.
Tengu was also found to resist removal through layered persistence and self-defense features that make infected devices difficult to clean. Researchers said it abuses watchdog behavior, installs fake systemd and init-based persistence, respawns processes, kills competing malware, re-executes filelessly, masquerades as legitimate processes, and corrupts reboot or shutdown binaries with the string ELFOOD. It further monitors its own integrity by reading Linux /proc memory-mapping data, calculating a SHA-256 baseline over part of its code, and rebooting the device if defenders try to terminate or modify it, complicating incident response and making simple reboot-based remediation unreliable.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Nozomi Networks Labs published indicators of compromise for the Tengu botnet, including its command-and-control address and sample hashes for six processor architectures. The disclosure accompanied defender guidance to patch devices, replace default credentials, segment networks, and monitor IoT and Linux systems.
Researchers revealed that Tengu uses watchdog abuse, fake systemd and init persistence, process respawning, competitor killing, fileless re-execution, process masquerading, and anti-debugging to remain on infected devices. They also reported integrity checks and reboot-triggering behavior when defenders attempt to terminate or modify the malware, making remediation more difficult.
Researchers documented Tengu as a newly observed Mirai-derived malware family targeting internet-facing IoT and embedded Linux devices, commonly delivered via Telnet brute force and a shell-script dropper. The analysis described capabilities beyond DDoS, including encrypted command-and-control, payload delivery, reconnaissance, persistence, and self-defense.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehelpnetsecurity.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcenozominetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.