HackerFeeds

CyberSecurity News

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

The Hacker News
· July 28, 2026

AI summary

A newly discovered botnet called Tengu, derived from Mirai, has the ability to reboot compromised Linux devices when its main process is terminated by defenders. This reboot is triggered by the device's hardware watchdog, which allows Tengu's other persistence mechanisms to attempt to relaunch the botnet. The botnet was observed spreading through Telnet credential brute force attacks. Tengu has capabilities that include distributed denial-of-service attacks. The botnet's ability to reboot devices gives it a way to potentially regain control after being stopped. Tengu's persistence mechanisms are designed to take advantage of this reboot capability to try to relaunch the botnet.

Read the full article at The Hacker Newsthehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.