Tengu Mirai-derived botnet persistence and payload activity
Malware Activity
Summary
Hide ▲
Show ▼
The Tengu botnet now shows self-defense persistence that can reboot a compromised Linux device via its hardware watchdog, helping it relaunch after defenders kill the main process. It also carries 25 DDoS methods, a SOCKS5 proxy, shell-command execution, and self-update logic that can fetch ELF or APK payloads. The sample was configured to contact 64[.]89.163.8:9931 and used Telnet credential brute force for initial access, indicating active malware tradecraft against exposed devices.
Related Happenings
Easy-day-js malware delivery through poisoned Mastra packages
Malware Activity
H score29
First: 22.06.2026 14:30
Last: 22.06.2026 14:30
Sources 1
About this happening:
A poisoned Mastra package chain delivered malware through easy-day-js, creating compromise risk across Windows, MacOS and Linux systems. The payload disabled TLS...
Easy-day-js malware delivery through poisoned Mastra packages
Malware ActivityAbout this happening: A poisoned Mastra package chain delivered malware through easy-day-js, creating compromise risk across Windows, MacOS and Linux systems. The payload disabled TLS...
Xlabs_v1 Mirai-derived ADB DDoS botnet
Malware Activity
H score22
First: 06.05.2026 23:21
Last: 06.05.2026 23:21
Sources 1
About this happening:
The xlabs_v1 Mirai-derived botnet has been exposed as a DDoS tool that abuses Android Debug Bridge (ADB) on internet-facing devices, expanding risk to Android, rou...
Xlabs_v1 Mirai-derived ADB DDoS botnet
Malware ActivityAbout this happening: The xlabs_v1 Mirai-derived botnet has been exposed as a DDoS tool that abuses Android Debug Bridge (ADB) on internet-facing devices, expanding risk to Android, rou...
UAT-9244 TernDoor, PeerTime, and BruteEntry malware activity
Malware Activity
H score22
First: 06.03.2026 01:19
Last: 06.03.2026 01:19
Sources 1
About this happening:
A China-linked malware cluster has been using TernDoor, PeerTime, and BruteEntry to compromise telecommunication providers in South America and turn infected s...
UAT-9244 TernDoor, PeerTime, and BruteEntry malware activity
Malware ActivityAbout this happening: A China-linked malware cluster has been using TernDoor, PeerTime, and BruteEntry to compromise telecommunication providers in South America and turn infected s...
Timeline
-
28.07.2026 18:01 1 articles · 2h ago
URLhaus records Mirai-related malware URLs on 64[.]89.163.8
Campaign Scope UpdateURLhaus records 17 malware URLs at 64[.]89.163.8, including a shell script, multiple ELF files tagged as Mirai, and an APK, indicating malicious hosting associated with the address.
Show sources
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process — thehackernews.com — 28.07.2026 18:01
-
28.07.2026 18:01 1 articles · 2h ago
URLhaus first sees additional payload entries on 64[.]89.163.8
Campaign Scope UpdateURLhaus first sees additional payload entries on 64[.]89.163.8 on July 7, 2026, adding a shell script, Mirai-tagged ELF files, and an APK to the malicious hosting set.
Show sources
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process — thehackernews.com — 28.07.2026 18:01
-
27.07.2026 03:00 2 articles · 1d ago
Nozomi Networks Labs publishes analysis of Tengu
Initial DisclosureNozomi Networks Labs publishes analysis of Tengu, a Mirai-derived botnet that targets compromised Linux devices, uses Telnet credential brute force for access, and can force a reboot through the hardware watchdog if defenders kill the main process. The analysis also describes a detached guardian, fake systemd and init persistence, cron-related persistence, hardcoded reboot and shutdown utilities, and support for 25 DDoS methods.
Show sources
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process — thehackernews.com — 28.07.2026 18:01
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process — thehackernews.com — 28.07.2026 18:01