# Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

> Tengu is a Mirai-derived Linux/IoT botnet, documented by Nozomi Networks Labs, that compromises internet-exposed embedded devices across six CPU architectures via Telnet credential brute force. It survives takedown attempts through a 60-second guardian-process respawn, fake systemd/init/RC/shell-startup persistence, binary immutability marking, and hardware-watchdog abuse that force-reboots the device if its process is killed, while offering 25 DDoS methods, SOCKS5 proxying, remote shell execution, and a custom ChaCha20/Poly1305-like encrypted C2 channel.

- **Published:** 2026-07-28T00:00:00Z
- **Last reviewed:** 2026-07-28T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1745
- **ID:** TL-2026-1745
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Tengu is a newly documented Mirai-lineage botnet targeting internet-facing embedded Linux systems — routers, cameras, DVRs, and other low-maintenance devices — that expose Telnet or similar remote administration services. Nozomi Networks Labs published the first technical analysis on 2026-07-27, and the finding was corroborated the following day by The Hacker News, Cyber Security News, Cyberpress, and Cryptika Cybersecurity.

Initial access is achieved through Telnet credential brute force against honeypot and internet-exposed devices. A shell-script dropper subsequently pulls an architecture-specific binary over HTTP, with samples confirmed for i386, amd64, MIPS, ARM, PowerPC, and m68k — giving Tengu one of the broadest hardware footprints observed in a current Mirai derivative.

What separates Tengu from generic Mirai clones is its anti-remediation depth. The primary malware process forks a detached guardian that checks the main process every 60 seconds and relaunches the installed binary if it is stopped. In parallel, a background worker masquerading as the kernel thread "[kworker/0:0]" reopens the hardware watchdog device where available, arms it with an approximately 30-second timeout, and issues keepalive signals only while the main malware process remains alive — meaning that if a defender kills the process without disabling the watchdog, the device is forced into a hardware reboot, destroying volatile forensic evidence and undoing in-memory remediation. Tengu additionally marks its installed binary immutable, installs fake systemd service units, alters init/RC scripts and shell startup files (cron-based persistence is present but described as unfinished/broken), and overwrites the ELF headers of a hardcoded list of reboot/shutdown utility binaries with the string "ELFOOD" — corrupting the very tools an administrator would use to cleanly power-cycle the device.

The malware also runs largely fileless: it uses memfd_create() to build an in-memory file named "systemd-journal" (falling back to /dev/shm/.journal if memfd is unavailable), deletes the filesystem-visible entry while keeping the file descriptor open, and re-executes itself via execve — leaving little on-disk footprint. The main process additionally rewrites its displayed command-line name to /usr/lib/systemd/systemd-journald to blend into normal process listings, and performs self-integrity checks by reading /proc memory-mapping information, computing a baseline SHA-256 value over part of its own code, and repeatedly comparing it (alongside monitoring for unexpectedly writable memory mappings) to detect tampering, patching, or analysis.

Command and control runs to 64.89.163.8 over TCP/9931. Registration, heartbeat, and command-output traffic are sent in plaintext, but server-issued commands and binary updates are protected with a custom ChaCha20/Poly1305-like authenticated encryption scheme. The C2 IP is XOR-obfuscated inside the binary, and dormant domain-generation-algorithm (DGA) logic is present but not observed in active use, suggesting a fallback capability the operator has not yet activated. The same host also serves an IPFS gateway (port 8080) used to retrieve additional ELF or APK payloads, including an Android APK whose delivery path suggests targeting of poorly secured Android TV boxes, though no confirmed Android infections have been documented.

Operational capabilities include 25 distinct DDoS methods, built-in SOCKS5 proxying (enabling proxy resale/relay abuse), arbitrary remote shell command execution, system and network reconnaissance data collection, self-updating, and the ability to detect and remove competing malware from a compromised device — a common Mirai-family trait aimed at monopolizing device resources.

URLhaus has tracked 17 malware URLs at 64.89.163.8 since 2026-06-17 (most recently 2026-07-07), comprising shell-script droppers, multiple ELF binaries tagged as Mirai, and one APK — corroborating that the C2 host doubles as an active malware distribution point. No CVE applies: this is a configuration/credential-exposure threat (exposed Telnet plus default or weak credentials) rather than a specific software vulnerability, so remediation is centered on reducing exposure and hardening credentials rather than patching.

## MITRE ATT&CK

- T1110 Brute Force
- T1133 External Remote Services
- T1059 Command and Scripting Interpreter
- T1543 Create or Modify System Process
- T1037 Boot or Logon Initialization Scripts
- T1546 Event Triggered Execution
- T1053 Scheduled Task/Job
- T1222 File and Directory Permissions Modification
- T1036 Masquerading
- T1620 Reflective Code Loading
- T1070 Indicator Removal
- T1027 Obfuscated Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1685 Disable or Modify Tools
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1090 Proxy
- T1573 Encrypted Channel
- T1071 Application Layer Protocol
- T1102 Web Service
- T1568 Dynamic Resolution
- T1105 Ingress Tool Transfer
- T1529 System Shutdown/Reboot
- T1489 Service Stop
- T1498 Network Denial of Service

## Sources

- [Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process](https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html)
- [Tengu Runs From Memory and Masquerades as systemd-journald to Hide on Linux Devices](https://cyberpress.org/tengu-masquerades-as-journald/)
- [New Tengu Mirai Botnet Reboots Your IoT Device When You Try to Kill It](https://cybersecuritynews.com/new-tengu-mirai-botnet/)
- [New Tengu Mirai Botnet Reboots Your IoT Device When You Try to Kill It](https://www.cryptika.com/new-tengu-mirai-botnet-reboots-your-iot-device-when-you-try-to-kill-it/)
- [URLhaus host record: 64.89.163.8](https://urlhaus.abuse.ch/host/64.89.163.8/)
- [Nozomi Networks Labs (primary research source cited by all secondary reporting)](https://www.nozominetworks.com/labs)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1745
