Tengu Botnet Uses Linux Watchdog to Survive Removal
🟠High | Source: The Hacker News A new botnet called Tengu, derived from the well-known Mirai malware, can hijack a Linux device’s hardware watchdog timer to force a reboot if defenders try to kill its process — giving its persistence mechanisms another chance to re-establish control. It spreads via brute-forced Telnet credentials and supports at least 25 DDoS attack methods. The self-healing capability makes manual incident response significantly harder on affected devices. ...