Tengu: Modernized Mirai IoT Malware Analysis
Score: 9/10

Tengu: Modernized Mirai IoT Malware Analysis

Tengu is an evolved Mirai-derived IoT botnet featuring AEAD-encrypted C2, proxy capabilities, and aggressive self-defense mechanisms targeting Linux and Android systems.

Executive Summary

Tengu represents a sophisticated evolution of the Mirai malware family, targeting exposed IoT and embedded Linux systems. Discovered by Nozomi Networks Labs, this botnet moves beyond simple DDoS attacks to include custom encrypted C2 protocols, SOCKS5 proxy functionality, and IPFS-based payload delivery. It demonstrates a high degree of operational security by targeting both ELF and APK binaries, expanding its reach to Android-based devices like TV boxes.

The malware is notably aggressive in its persistence and self-defense posture. It employs a watchdog mechanism that triggers a system reboot if the malware process is terminated and actively overwrites reboot-related system binaries (ELF bricking) to prevent remediation. Additionally, Tengu features a 'competitor killing' loop that scans for and terminates rival IoT malware, ensuring exclusive control over the compromised host.

For industrial and enterprise organizations, Tengu poses a significant risk as it can be used for volumetric DDoS, network reconnaissance, and as a resilient foothold for proxying malicious traffic. The convergence of IoT vulnerabilities and modernized malware techniques underscores the need for immediate hardening of internet-facing embedded devices and robust network segmentation.

Key Details

Threat Name

Tengu IoT Malware

Affects

—

Adversary

—

Malware/Tools

Tengu, Mirai, Tsunami, Mozi, Gafgyt, Hajime, Qbot

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance9
Enterprise Relevance8
Clarity & Structure8
Technical Depth9

Sources