Executive Summary
Tengu is a recently identified 32-bit x86 Linux ELF botnet that demonstrates sophisticated survival and persistence techniques. While its behavior and internal artifacts reference known families like Mirai, Gafgyt, and Tsunami, it is distinct in its implementation of a 'System Helper Service' and extensive cross-distribution persistence. The malware prioritizes stealth by masquerading as a kernel worker thread and protecting itself from the Linux OOM killer.
Technically, the botnet employs XOR-obfuscated command-and-control (C2) communication, specifically targeting 64.89.163[.]8:9931. Its primary function is the execution of denial-of-service attacks, supported by raw IPv4/UDP flooding, SSH banner scanning, and HTTP request generation with spoofed Cloudflare headers. It also includes SOCKS5 and HTTP CONNECT proxy capabilities, likely used to tunnel malicious traffic through compromised hosts.
The urgency for this threat is moderate to high for organizations managing Linux servers or IoT infrastructure. Tengu's ability to persist across systemd, OpenWrt (procd), and SysV init environments ensures high resilience on various Linux distributions, making removal difficult once a foothold is established.
