Quick Takeaways
- Tengu, a Mirai-derived botnet, exploits Linux devices’ hardware watchdogs and persistence mechanisms, including systemd, init scripts, and cron jobs, to maintain control after reboots.
- The malware supports 25 DDoS techniques, can run SOCKS5 proxies, execute shell commands, and update with ELF or APK payloads, posing a broad threat surface.
- It communicates with a C2 server via plaintext, uses custom encryption, and targets IoT devices like Android TV boxes, risking large-scale disruption and device compromise.
Threat, Attack Techniques, and Targets
The Tengu botnet is a new malware that is related to Mirai. It can reboots compromised Linux devices using their hardware watchdogs when defenders kill its process. It mainly spreads through brute-force attacks on Telnet credentials. Once inside, it supports 25 different methods for launching distributed denial-of-service (DDoS) attacks. Tengu can also run a SOCKS5 proxy, execute shell commands, and collect system and network data. It can update itself and download more payloads like ELF or APK files. This malware works on various architectures including i386, amd64, MIPS, ARM, PowerPC, and m68k. It does not target specific vendors or models but targets devices that can be compromised through weak credentials or open services.
Impact, Security Implications, and Remediation Guidance
Tengu poses serious security risks because it can attempt to reboot devices automatically if its process is killed. This self-healing ability makes it hard to remove. The malware’s ability to run multiple hidden persistence routines means that it can stay active on infected devices for a long time. This can allow attackers to use compromised devices for DDoS attacks or other malicious activities. A key security concern is that Tengu can interfere with normal device shutdowns by overwriting utility headers. To reduce these threats, organizations should remove internet exposure from Telnet and other unnecessary services. They should also change default credentials, update device firmware, segment IoT networks, and review systemd, init scripts, and cron jobs before restoring devices. Since detailed remediation steps are not provided, organizations should seek guidance from the device vendors or relevant security authorities.
Discover More Technology Insights
Explore the future of technology with our detailed insights on Artificial Intelligence.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
