THE Tengu botnet, disclosed by Nozomi Networks Labs on July 27, 2026, is a modernized variant of the Mirai IoT botnet, targeting internet-facing embedded Linux devices like routers and cameras. It employs Telnet brute-force attacks for initial access, followed by downloading specific payloads. Tengu boasts enhanced capabilities like 25 DDoS methods, encrypted command and control communications, and advanced self-defense mechanisms, making it difficult to detect and remove.
The malware establishes persistence through various means, including spoofing system services and avoiding shutdown commands. Best practices for defense include securing Telnet access, updating firmware, and monitoring for suspicious processes.