Tengu is a Mirai-derived botnet malware family targeting Linux-based IoT and embedded devices, with samples compiled for i386, amd64, MIPS, ARM, PowerPC, and m68k architectures. It recruits devices through Telnet credential brute-forcing, followed by a shell-script dropper that downloads and executes architecture-specific binaries. Its functionality combines distributed denial-of-service attacks, traffic proxying, remote command execution, reconnaissance, payload delivery, and extensive persistence and self-defense mechanisms.
Tengu supports 25 denial-of-service methods, including volumetric floods and protocol-specific attacks. Infected devices can relay traffic through SOCKS5 proxies, execute arbitrary shell commands, and transmit command output, system metadata, and network configuration information to operators. The malware can update itself and retrieve additional ELF executables or Android APK packages. APK-handling functionality does not establish confirmed Android infections. Command-and-control uses plaintext registration, heartbeats, and command output alongside authenticated encryption for incoming commands and updates.
Persistence mechanisms include systemd services, init and startup scripts, shell startup modifications, and a detached guardian process that relaunches the main component. Tengu can mark its installed executable immutable and abuse the device watchdog: keepalive signals stop when the main malware process terminates, potentially forcing a reboot after approximately 30 seconds and allowing startup persistence to restore the infection. It also corrupts the ELF headers of shutdown and reboot utilities, interfering with normal administrative recovery.
Tengu conceals itself through system-process masquerading, runtime string decryption, and memory-based re-execution. Additional defenses include anti-debugging, code-integrity checks, and termination of competing botnet processes. No specific threat actor or confirmed infection scale has been established. The Linux botnet should not be conflated with the separately reported ransomware-as-a-service operation also named Tengu.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
"[Tengu] attempts to survive reboots through ... scheduled tasks..."
Besides persistence through systemd and init.d... Tengu tries to use cron, the tool for scheduling recurring tasks, though Nozomi found this method doesn’t work as intended.
...добавляет init- и rc-скрипты, меняет стартовые файлы оболочки...
"[Tengu] attempts to survive reboots through ... scheduled tasks..."
Besides persistence through systemd and init.d... Tengu tries to use cron, the tool for scheduling recurring tasks, though Nozomi found this method doesn’t work as intended.
Tengu, observed by Nozomi Networks Labs, spreads through Telnet credential brute-forcing
Также для закрепления в системе Tengu создает фиктивный systemd...
"[Tengu] attempts to survive reboots through ... SysV and OpenWrt startup scripts..."
"[Tengu] attempts to survive reboots through ... local startup files."
Its unique persistence strategy involves a guardian process that monitors the main malware and relaunches it if stopped. Critically, it can also leverage the hardware watchdog timer; if the main process is killed, the watchdog is left unfed, causing a device reboot, which then allows Tengu's other persistence methods to reactivate.
...добавляет init- и rc-скрипты, меняет стартовые файлы оболочки...
"[Tengu] attempts to survive reboots through ... scheduled tasks..."
Besides persistence through systemd and init.d... Tengu tries to use cron, the tool for scheduling recurring tasks, though Nozomi found this method doesn’t work as intended.
Tengu, observed by Nozomi Networks Labs, spreads through Telnet credential brute-forcing
Также для закрепления в системе Tengu создает фиктивный systemd...
"[Tengu] attempts to survive reboots through ... SysV and OpenWrt startup scripts..."
"[Tengu] attempts to survive reboots through ... local startup files."
Its unique persistence strategy involves a guardian process that monitors the main malware and relaunches it if stopped. Critically, it can also leverage the hardware watchdog timer; if the main process is killed, the watchdog is left unfed, causing a device reboot, which then allows Tengu's other persistence methods to reactivate.
To reduce the chance of detection, Tengu decrypts its strings only during execution...
...один из компонентов Tengu создает отдельный фоновый процесс, который маскируется под системный поток [kworker/0:0]...
"Tengu replaces its visible process name with a randomized kernel-worker-style label, making it resemble a Linux kernel worker in ordinary process listings."
Tengu, observed by Nozomi Networks Labs, spreads through Telnet credential brute-forcing
"It can gather basic host and network details..."
Эта малварь поддерживает 25 видов DDoS-атак, может развертывать SOCKS5-прокси, выполнять шелл-команды, собирать информацию о системе и сети...
Another process repeatedly scans running processes and terminates competing botnets.
Также обнаружилось, что Tengu мог получать идентификаторы дополнительных файлов с управляющего сервера злоумышленников...
"[Tengu can] build authenticated HTTP CONNECT and SOCKS5 proxy functions" and "infected hosts can also be used to relay traffic."
“With data secured, the attackers deploy the encryptor across as many systems as possible.”
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hands-on-keyboard ransomware-as-a-service operation employing double extortion through data theft and encryption.
A 32-bit Linux ELF bot that masquerades as a kernel worker process, reduces its likelihood of out-of-memory termination, suppresses standard streams, and establishes persistence through systemd, SysV/OpenWrt scripts, scheduled tasks, and startup files. It supports raw and socket-based UDP floods, HTTP GET/POST/HEAD request floods, SSH banner/key-exchange activity, and authenticated HTTP CONNECT/SOCKS5 proxying. Initial access and direct code lineage to Mirai are unconfirmed.
A stripped, statically linked 32-bit Linux ELF targeting servers, embedded systems, and IoT-adjacent devices. It masquerades as a kernel worker, adjusts out-of-memory controls to resist termination, and establishes persistence through multiple Linux startup mechanisms. It collects host and network information, supports authenticated HTTP CONNECT and SOCKS5 proxies, and generates raw UDP, datagram UDP, HTTP, and SSH-handshake traffic for disruption. Its recovered command-and-control endpoint is 64[.]89[.]163[.]8:9931. Initial infection methods, victim counts, and confirmed campaign impact remain unknown; the SSH functionality was not shown to exploit authentication or attack credentials.
Mentioned as a prior Japanese-themed ransomware group for comparison/background.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.