Find notable cyber news and cases, enriched with sources, timelines, and signals.

Tengu Mirai-derived botnet persistence and payload activity

Malware Activity
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

The Tengu botnet now shows self-defense persistence that can reboot a compromised Linux device via its hardware watchdog, helping it relaunch after defenders kill the main process. It also carries 25 DDoS methods, a SOCKS5 proxy, shell-command execution, and self-update logic that can fetch ELF or APK payloads. The sample was configured to contact 64[.]89.163.8:9931 and used Telnet credential brute force for initial access, indicating active malware tradecraft against exposed devices.

Related Happenings

Easy-day-js malware delivery through poisoned Mastra packages

Malware Activity
H score29 First: 22.06.2026 14:30 Last: 22.06.2026 14:30 Sources 1

About this happening: A poisoned Mastra package chain delivered malware through easy-day-js, creating compromise risk across Windows, MacOS and Linux systems. The payload disabled TLS...

Xlabs_v1 Mirai-derived ADB DDoS botnet

Malware Activity
H score22 First: 06.05.2026 23:21 Last: 06.05.2026 23:21 Sources 1

About this happening: The xlabs_v1 Mirai-derived botnet has been exposed as a DDoS tool that abuses Android Debug Bridge (ADB) on internet-facing devices, expanding risk to Android, rou...

UAT-9244 TernDoor, PeerTime, and BruteEntry malware activity

Malware Activity
H score22 First: 06.03.2026 01:19 Last: 06.03.2026 01:19 Sources 1

About this happening: A China-linked malware cluster has been using TernDoor, PeerTime, and BruteEntry to compromise telecommunication providers in South America and turn infected s...

Timeline

  1. 27.07.2026 03:00 2 articles · 1d ago

    Nozomi Networks Labs publishes analysis of Tengu

    Initial Disclosure

    Nozomi Networks Labs publishes analysis of Tengu, a Mirai-derived botnet that targets compromised Linux devices, uses Telnet credential brute force for access, and can force a reboot through the hardware watchdog if defenders kill the main process. The analysis also describes a detached guardian, fake systemd and init persistence, cron-related persistence, hardcoded reboot and shutdown utilities, and support for 25 DDoS methods.

    Show sources