BoletimSecJuly 29, 2026🇵🇹Translated from Portuguese

Tengu Botnet Modernizes Mirai with 25 DDoS Methods and Advanced Persistence on IoT and Embedded Linux

A new botnet called Tengu is actively infecting Internet of Things devices and embedded Linux systems to perform denial-of-service attacks, redirect traffic, and maintain long-term access on compromised hosts.

The threat is a modernized variant of the well-known Mirai malware. Infection typically begins with brute-force attempts against exposed Telnet services. After obtaining valid credentials, a downloader script retrieves the appropriate malware binary matching the device architecture.

Tengu uses partially encrypted communication channels with its command-and-control infrastructure. Operators can execute arbitrary commands, gather detailed system and network information, update the implant, and convert the device into a SOCKS5 proxy.

The botnet ships with 25 DDoS attack methods, including UDP, TCP, and ICMP floods. It can also target HTTP, DNS, NTP, SSH, SMTP, FTP, SIP services as well as Minecraft servers and hosts running the Source Engine and Quake protocols.

Persistence and Self-Protection Mechanisms

The primary distinguishing features of Tengu are its advanced persistence and defensive capabilities. A secondary monitoring process checks the main malware every 60 seconds and automatically restarts it if the process is terminated.

  • Fake systemd services and modified init scripts ensure the malware reactivates after reboots.
  • The botnet manipulates the device watchdog timer to trigger a reboot whenever its process is removed.
  • It corrupts legitimate shutdown utilities and actively eliminates competing malware that attempts to take control of the same device.

Related articles

HabrMalware & Botnets

Network Traffic Analysis Reveals 75% Malware Threats Over 10 Months of Monitoring

Positive Technologies analyzed anonymized data from PT Sandbox and PT Network Attack Discovery collected between October 2025 and July 2026. The study found that malicious software accounted for 75% of all detected threats in organizational network traffic. Information-stealing trojans made up 24% of malware samples, with 85% of those focused on credential theft. RATs, loaders, and ransomware each represented smaller but high-impact shares. Legacy vulnerabilities such as CVE-2017-0199 and CVE-2017-11882 remained active attack vectors. Activity from groups including MustangPanda, TA505, and APT37 was observed across finance, manufacturing, and government sectors.

BoletimSecMalware & Botnets

HEAVYGRAM Spyware Uses Telegram Bots for Command and Control Against Iranian Targets

Researchers at Group-IB have published a detailed analysis of HEAVYGRAM, a spyware family that abuses the Telegram messaging platform as its command-and-control infrastructure. The malware family was first observed in the second half of 2023 and has since been linked with moderate confidence to the Handala Hack group. Instead of operating dedicated servers, the operators rely on Telegram bots, accounts, and groups to register infected hosts, receive commands, exfiltrate stolen data, and deliver additional payloads. Once active, HEAVYGRAM captures screenshots, records audio, harvests cached files, and steals data from Telegram Desktop installed on the victim machine. The campaign primarily targets Iranian journalists, dissidents, and individuals opposed to the Iranian government. Infection vectors include malicious files distributed via messengers, disguised as legitimate applications such as Pictory, KeePass, or Telegram-related tools, sometimes delivered as HTML applications or scripts.

BoletimSecMalware & Botnets

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens in Brazil

Elastic Security Labs researchers have detailed the operations of the KREMLIN banking malware, tracked under the identifier REF9334, which targets Chrome and Edge browsers to harvest credentials and session tokens. The campaign focuses almost exclusively on Brazil, with 98 percent of the 1,515 identified infections located in the country and impersonating a dozen Brazilian banks. Infection begins with multi-stage JavaScript loaders disguised as banking documents, invoices, or corporate papers that require manual execution by the victim. The loaders then deploy C++ installers and malicious browser extensions that modify the Secure Preferences file, enable developer mode, and overwrite protection objects with forged metadata using a technique called Phantom Extension. Once active, the extension collects session tokens, cookies, sessionStorage and localStorage data, 15 days of browsing history, screenshots, open tab information, and full HTML of visited pages. The operation has run since May 2025 across seven distinct campaigns and began using Ethereum smart contracts for infrastructure on 19 May 2026.

BoletimSecMalware & Botnets

Malicious Twitch Extension Steals OAuth Tokens from Nearly 31,000 Users

A browser extension posing as an enhancement for Twitch has been stealing OAuth authentication tokens from approximately 31,000 users across Chrome and Firefox. The extension, known as Twitch Enhanced Viewer or JeetBot, was discovered by researcher Kush Pandya of Socket. It promised 1080p streaming in restricted regions and an ad-free experience while covertly exfiltrating session tokens to attacker-controlled servers. The tokens were transmitted in plaintext via network-layer redirects, allowing full access to chat functions, private messages, and account settings. Both the Chrome version with around 30,000 installations since June 26, 2025, and the Firefox version with 604 users since July 7, 2025, remained available in official stores at the time of reporting. Users are advised to immediately disable the extension and revoke active Twitch sessions to invalidate stolen tokens.