← Back to Feed

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

July 28, 2026 · The Hacker News · Severity: MEDIUM

A new Mirai-derived botnet called Tengu uses a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process, giving its other persistence mechanisms another chance to relaunch. The botnet supports 25 DDoS methods, SOCKS5 proxy, shell command execution, and system data collection, reaching honeypots via Telnet credential brute force across multiple architectures including i386, amd64, MIPS, ARM, and PowerPC.

Key Takeaways

  • Tengu uses hardware watchdog timers to reboot compromised Linux devices when its main process is killed
  • The botnet is Mirai-derived and supports 25 different DDoS attack methods
  • It can run a SOCKS5 proxy, execute shell commands, and collect system and network data
☕ Buy a Coffee