Tengu: Reverse Engineering a Mirai-Style Linux Botnet
Score: 9/10

Tengu: Reverse Engineering a Mirai-Style Linux Botnet

Tengu is a Linux-based botnet targeting IoT and server environments, utilizing kernel-worker masquerading and multiple persistence mechanisms to facilitate DDoS attacks.

Executive Summary

Tengu is a recently identified 32-bit x86 Linux ELF botnet that demonstrates sophisticated survival and persistence techniques. While its behavior and internal artifacts reference known families like Mirai, Gafgyt, and Tsunami, it is distinct in its implementation of a 'System Helper Service' and extensive cross-distribution persistence. The malware prioritizes stealth by masquerading as a kernel worker thread and protecting itself from the Linux OOM killer.

Technically, the botnet employs XOR-obfuscated command-and-control (C2) communication, specifically targeting 64.89.163[.]8:9931. Its primary function is the execution of denial-of-service attacks, supported by raw IPv4/UDP flooding, SSH banner scanning, and HTTP request generation with spoofed Cloudflare headers. It also includes SOCKS5 and HTTP CONNECT proxy capabilities, likely used to tunnel malicious traffic through compromised hosts.

The urgency for this threat is moderate to high for organizations managing Linux servers or IoT infrastructure. Tengu's ability to persist across systemd, OpenWrt (procd), and SysV init environments ensures high resilience on various Linux distributions, making removal difficult once a foothold is established.

Key Details

Threat Name

Tengu Linux Botnet

Affects

—

Adversary

—

Malware/Tools

Tengu, Mirai, tsunami, gafgyt, hajime

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance9
Enterprise Relevance8
Clarity & Structure10
Technical Depth10

Sources