Security researchers at Nozomi Networks Labs report that a newly identified, Mirai-derived IoT botnet called Tengu can improve its resilience when defenders attempt to disrupt it. According to multiple accounts, Tengu is able to force an infected Linux device to reboot if the bot’s main process is killed. The reboot gives the malware’s persistence mechanisms an additional opportunity to restart and relaunch the malicious components.
Researchers say they first observed the malware through its interaction with honeypots exposed to internet traffic. The reported infection pathway includes Telnet credential brute-force attempts, through which the malware’s dropper gains access and reaches those environments.
Tengu is described as supporting distributed denial-of-service activity, with one report specifying 25 DDoS-related components or attack capabilities. The botnet’s behavior is characterized as a shift toward surviving operational disruption, using device-level functions such as a hardware watchdog/reboot trigger in response to defensive actions.
The findings focus on how Tengu maintains control after partial takedown attempts, highlighting persistence as a key operational feature of the botnet.