logo

Tengu Botnet Is a Modernized Mirai Variant That Fights to Stay on IoT Devices

ID: f27add53-a7a5-586f-9ac2-a9dcd190edba

STIX ID: report--f27add53-a7a5-586f-9ac2-a9dcd190edba

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: Do Son

...
...

Nozomi Networks Labs disclosed Tengu, a Mirai-derived IoT botnet that infects Internet-facing embedded Linux devices via Telnet brute force and an HTTP shell-script dropper; it supports multiple architectures, 25 DDoS methods, SOCKS5 proxying, encrypted authenticated commands, IPFS and APK payload delivery, and robust self-defense/persistence (memfd_create in-memory execution, watchdog relaunch, reboot-triggered persistence and corruption of recovery binaries). The report emphasizes hardening against removal and anti-analysis measures, offers defender guidance (disable Telnet, change defaults, segment IoT), and provides technical details of its C2, update paths, and capabilities while naming no operator or victim counts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.