Tengu botnet reboots Linux devices to survive removal A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a machine-learning system the company uses to identify malware families that do not match known signatures. Researchers first observed the dropper reaching their honeypots through Telnet credential brute-force attacks. Tengu isn’t just another Mirai variant Nozomi’s analysis found a range of capabilities built into the malware, including an encrypted channel for issuing commands, the ability to relay an operator’s traffic through the infected device, delivery of new payloads, collection of system and network details, and a wide set of denial-of-service functions covering several protocols. “It also includes multiple persistence and self-defense mechanisms designed to keep the malware running on compromised Linux-based devices and make recovery more difficult,” the researchers wrote. Tengu retains several Mirai characteristics, including plaintext registration messages and reused denial-of-service code. It also adds a SOCKS5 proxy, shell command execution, system and network reconnaissance, and the ability to download ELF binaries or Android APKs through an IPFS gateway hosted on the same command-and-control (C2) server. Researchers believe the APK support targets poorly secured Android TV boxes and similar Android-based devices. The malware also includes 25 DDoS methods. Built to survive removal Besides persistence through systemd and init.d, two Linux systems that automatically launch services when a device starts up, Tengu tries to use cron, the tool for scheduling recurring tasks, though Nozomi found this method doesn’t work as intended. The malware creates a hidden guardian process that checks every 60 seconds whether the main malware process is still running and restarts it if necessary. Tengu also abuses the Linux hardware
Tengu botnet reboots Linux devices to survive removal
Read the original article
helpnetsecurity.com →