Tengu Botnet Uses Watchdog to Reboot Compromised Linux Devices
A new Mirai‑derived botnet, Tengu, exploits Linux watchdog timers to reboot devices after its process is killed, adding fresh persistence tricks for IoT attackers.
A new Mirai‑derived botnet, Tengu, exploits Linux watchdog timers to reboot devices after its process is killed, adding fresh persistence tricks for IoT attackers.
The Dysphoria botnet now controls ~200,000 devices, using blockchain domains for C2 and shifting between DDoS and proxy roles. Learn the risks and defenses.
The NadMesh botnet is siphoning AWS keys, Kubernetes tokens, and AI model data from poorly secured AI services, exposing massive credential leaks and ongoing exploit traffic.
Google and partners disrupt NetNut, a residential proxy botnet of at least 2 million infected devices, cutting off its malicious traffic and shaking the proxy market.
The FBI, with industry partners, seized hundreds of domains tied to NetNut’s residential proxy botnet, disrupting a network of over 2 million compromised devices.