Linux Bot Tengu Malware: Everything You Need to Know About This New Linux DDoS Threat

Cybersecurity researchers have uncovered a newly analyzed piece of Linux malware known as Linux Bot Tengu Malware, a sophisticated threat designed to quietly infect Linux systems, maintain persistence, and launch distributed denial-of-service (DDoS) attacks when instructed by its operators. Unlike many older Linux botnets that rely on basic flooding techniques, Tengu combines stealth, persistence, proxy functionality, and multiple attack methods into a single malware framework, making it a significant concern for organizations running Linux servers, embedded devices, and internet-connected IoT equipment.

The malware was reverse engineered by researchers at Reverser.space, who identified it as a stripped 32-bit Linux ELF binary capable of disguising itself as a legitimate kernel worker process. While the researchers did not attribute the malware to any known threat actor or confirm a widespread attack campaign, the technical capabilities demonstrate that Tengu is designed for long-term compromise and remote control rather than short-lived attacks.

One of the most notable aspects of Linux Bot Tengu Malware is its ability to blend into normal Linux operations. By changing its visible process name to resemble a kernel worker thread, it becomes much less likely to attract attention during routine administrative checks. Combined with several persistence techniques and a hidden command-and-control infrastructure, the malware can remain active even after system reboots unless administrators perform a comprehensive forensic investigation.

What Is Linux Bot Tengu Malware?

The Linux Bot Tengu Malware is a Mirai-style Linux bot that targets servers, embedded Linux systems, networking equipment, and IoT devices. Researchers analyzed a statically linked 32-bit ELF executable that was stripped of debugging information, making reverse engineering more difficult.

Unlike ransomware or information-stealing malware, Tengu focuses primarily on maintaining remote control over infected devices and using them as part of a larger botnet. Once active, the malware can receive commands from a remote command-and-control (C2) server to launch different types of denial-of-service attacks, proxy network traffic, collect system information, and execute additional functions.

Researchers describe it as “Mirai-style” because of its architecture and capabilities rather than confirmed shared source code. At present, there is no public evidence that Tengu is a direct descendant of the original Mirai malware.

How Linux Bot Tengu Malware Hides From Administrators

One of the most impressive stealth techniques used by Linux Bot Tengu Malware is process masquerading. Instead of running under an obvious executable name, the malware changes its process title to resemble legitimate Linux kernel worker threads.

For example, administrators may observe names similar to:

  1. [kworker/1:0]
  2. [kworker/2:1]
  3. [kworker/3:2]

Since Linux systems naturally run numerous kernel worker processes, these names often blend into standard process listings viewed through tools such as ps, top, or htop. While experienced administrators can still identify the malware by inspecting the executable path or parent process, the disguise significantly reduces the likelihood of immediate detection.

The malware also modifies Linux out-of-memory (OOM) settings to reduce the chances of being terminated when system memory becomes scarce. After initialization, it closes its standard input, output, and error streams before continuing execution quietly in the background.

Persistence Across Multiple Linux Distributions

Persistence Across Multiple Linux Distributions

Persistence is one of Tengu’s strongest capabilities. Rather than relying on a single startup mechanism, the malware attempts to survive system reboots using several methods depending on the target operating system.

Researchers observed support for systemd services, traditional SysV init scripts, OpenWrt startup files, scheduled cron tasks, and user-level startup scripts. This flexibility enables the malware to remain active across enterprise Linux servers, embedded network appliances, and lightweight Linux distributions commonly found in routers and IoT devices.

The malware also retrieves its executable path from the Linux /proc filesystem, allowing it to continue functioning even if the original executable has been deleted after launch. Such techniques increase the difficulty of completely removing the infection without a detailed forensic investigation.

DDoS Attack Capabilities

DDoS Attack Capabilities

The primary objective of Linux Bot Tengu Malware is to participate in distributed denial-of-service attacks. Researchers identified multiple attack modules capable of overwhelming both network infrastructure and application services.

The malware supports two separate UDP flooding techniques. One uses raw sockets to create custom IPv4 packets with attacker-controlled header values, allowing packet spoofing where supported by the network. The second relies on standard UDP sockets, ensuring compatibility on systems where raw sockets are unavailable.

Beyond network-layer attacks, Tengu also performs HTTP GET, POST, and HEAD request floods while generating randomized forwarding headers to complicate defensive filtering. Another module performs SSH banner and key-exchange handshakes. Although researchers found no evidence that this function attempts password guessing or exploitation, repeated handshake requests alone can consume server resources when executed at scale.

Unlike simple flooders, Tengu also includes SOCKS5 and HTTP CONNECT proxy functionality, allowing compromised devices to relay attacker traffic or hide the origin of malicious communications.

Why Linux Bot Tengu Malware Is a Serious Security Threat

What makes Linux Bot Tengu Malware particularly dangerous is not just its ability to launch DDoS attacks, but the combination of stealth, persistence, and versatility. Unlike older Linux malware that focused on a single attack method, Tengu includes multiple modules that allow attackers to adapt their tactics based on the target and network environment.

For example, the malware can launch network-layer UDP floods, application-layer HTTP floods, and SSH handshake requests from the same infected machine. This multi-vector approach makes it harder for defenders to block malicious traffic because attackers can quickly switch between different attack methods.

Another concern is the malware’s proxy capability. By enabling SOCKS5 and HTTP CONNECT proxy services, compromised devices can be used to relay malicious traffic, conceal the origin of attacks, or support additional cybercriminal activities. This means an infected Linux server may unknowingly become part of a much larger malicious infrastructure.

Although researchers have not confirmed the size of the botnet or identified the threat actor behind Tengu, its technical capabilities indicate that it was developed for long-term operations rather than one-off attacks.

Command-and-Control Infrastructure

Like most modern botnets, Linux Bot Tengu Malware relies on a command-and-control (C2) server to receive instructions from its operators.

The reverse engineering report identified a hardcoded endpoint that allows infected systems to communicate with the attacker’s infrastructure. Through this connection, operators can issue commands, trigger attack modules, and manage compromised devices remotely.

Researchers also found that the malware collects basic information about the infected host before establishing communication with the C2 server. This helps attackers understand the capabilities of each compromised device and decide how it can best contribute to the botnet.

Since command-and-control servers can change over time, organizations should not rely solely on blocking a single IP address. Instead, they should monitor unusual outbound connections, unexpected proxy activity, and suspicious traffic patterns that could indicate malware communication.

Indicators of Compromise (IoCs)

Organizations should look for the following indicators that may suggest a Tengu infection:

  1. Suspicious processes with names resembling [kworker/x:y] but linked to unexpected executable paths.
  2. Unknown systemd services or SysV init scripts created without administrator approval.
  3. Unexpected files such as /etc/init.d/tengu or /tmp/.proxy.pid.
  4. Outbound connections to suspicious command-and-control servers.
  5. Repeated bursts of UDP traffic, unusual HTTP requests, or excessive SSH handshake activity.
  6. Modified Linux Out-Of-Memory (OOM) settings designed to keep a process alive.
  7. Unrecognized cron jobs or startup scripts that persist after reboot.

These indicators should always be investigated alongside endpoint telemetry and memory analysis to avoid false positives.

How to Detect Linux Bot Tengu Malware

How to Detect Linux Bot Tengu Malware

Detecting Linux Bot Tengu Malware requires more than a traditional antivirus scan. Because the malware uses stealth techniques to blend into legitimate Linux processes, administrators should focus on behavioral analysis rather than process names alone.

Security teams should verify the executable path of any suspicious kernel worker process, inspect parent-child process relationships, review startup services, and compare running processes with known system binaries. Endpoint Detection and Response (EDR) solutions, Linux audit logs, and memory forensics can provide valuable visibility into suspicious activity.

Regular network monitoring is equally important. Unexpected outbound connections, abnormal UDP traffic, repeated HTTP requests, or unusual SSH handshakes may indicate that a compromised device is participating in a botnet.

How Organizations Can Protect Their Linux Systems

While the initial infection vector for Tengu remains unknown, organizations can significantly reduce their risk by following established cybersecurity best practices.

Keep Linux systems, embedded devices, and network appliances updated with the latest security patches. Disable unnecessary internet-facing services, particularly Telnet and unused SSH access. Enforce strong authentication, use multi-factor authentication where possible, and restrict administrative access to trusted networks.

Continuous monitoring should include endpoint detection, log analysis, and network traffic inspection. Administrators should also routinely audit startup services, scheduled tasks, and user accounts for unauthorized changes.

For organizations managing IoT devices, network segmentation is especially important. Separating critical infrastructure from internet-facing devices limits the impact of a successful compromise and reduces opportunities for attackers to move laterally through the network.

Final Thoughts

The Linux Bot Tengu Malware demonstrates how Linux-focused threats continue to evolve beyond simple denial-of-service tools. By combining process masquerading, multiple persistence methods, proxy capabilities, and diverse DDoS techniques, Tengu offers attackers a flexible platform capable of compromising a wide range of Linux environments.

Although researchers have not confirmed a large-scale campaign, the malware’s sophisticated design highlights the importance of proactive defense. Organizations should treat exposed Linux servers, embedded devices, and IoT systems as high-value targets, maintain strong patch management practices, and invest in behavioral monitoring capable of detecting advanced threats.

As cybercriminals increasingly adopt stealth techniques and modular malware architectures, understanding threats like Linux Bot Tengu Malware is essential for improving enterprise resilience and protecting critical digital infrastructure.

Internal Links

  1. AI News → /artificial-intelligence/
  2. Tech News → /tech-news/
  3. Reviews → /reviews-buying-guides/

DoFollow External Links

  1. https://reverser.space/
  2. https://www.cisa.gov/
  3. https://attack.mitre.org/
  4. https://owasp.org/

Leave a Comment