Security · 16h ago
Tengu Botnet Uses Hardware Watchdog to Survive Defenders' Kill Commands
A new Mirai-derived botnet called Tengu can reboot compromised Linux devices when its main process is killed, using the hardware watchdog to trigger a restart. Nozomi Networks Labs observed the dropper reaching honeypots via Telnet brute force. Tengu supports 25 DDoS attack methods, making it a persistent threat.
Meridian48 take
The hardware watchdog trick is a clever evasion, but the reliance on Telnet brute force limits its spread to poorly secured devices.
Read the full reporting
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process →
The Hacker News
botnetlinux-security