news.mlab.sh
Back to the feed
threat-intel

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

High
Image: The Hacker News
Summary

A new Mirai-derived botnet, Tengu, is leveraging hardware watchdog timers and other persistence mechanisms to re-establish itself on compromised Linux devices, even after defenders attempt to kill its main process. The botnet utilizes various DDoS methods, executes shell commands, and can update itself with new payloads, including Android packages. Nozomi Networks Labs has identified the botnet and recommends mitigation steps, including removing unnecessary services and segmenting IoT networks.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.