Security News Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Parkinsond

Level 64
Thread author
Verified
Top Poster
Well-known
Dec 6, 2023
5,351
16,678
6,269
Tengu supports 25 distributed denial-of-service (DDoS) methods. It can also run a SOCKS5 proxy, execute shell commands, and collect system and network data. The malware can update itself and retrieve additional Executable and Linkable Format (ELF) or Android package (APK) payloads.

The analyzed sample was configured to communicate with a command-and-control (C2) server at 64[.]89.163.8 over TCP port 9931. Registration, heartbeat traffic, and command output are sent in plaintext, while server commands and updates use a custom ChaCha20/Poly1305-like authenticated encryption scheme.

URLhaus independently recorded 17 malware URLs at 64[.]89.163.8 beginning June 17, 2026. The records included a shell script, multiple ELF files tagged as Mirai, and an APK. URLhaus's most recent payload entries were first seen on July 7, and all 17 URLs were offline as of July 28.

 
All URLs are HTTP.
Only “HTTPS Strict” resolves the issue.
It's also possible to block JavaScript for all HTTP websites.

A simpler solution is to use the 3P-Matrix-lite extension, which,even at level 2,blocks HTTP connections + all ports that can be abused (not port 443).
More info in the extension's thread.
 

You may also like...