Utopia Tech
SecurityAI-assisted1 min read

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

A new Mirai-based botnet named Tengu has been discovered with advanced persistence capabilities, including the ability to trigger device reboots via hardware watchdog timers when its main process is terminated. Nozomi Networks Labs detected the malware spreading through Telnet brute-force attacks on Linux devices. The botnet supports at least 25 different distributed denial-of-service attack metho

UT

Utopia Tech

July 28, 2026 · 1 min read

Share

A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force. Tengu supports 25 distributed denial-of-service (

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content