Logo

New Self-Reviving Botnet Targets Weak Business Network Devices

Security researchers have discovered a new piece of malware called Tengu that does something particularly stubborn: if you manage to kill the malicious process running on an infected device, it can trigger the device’s own hardware “watchdog” feature to force a reboot, giving the malware another chance to relaunch itself. It sounds like something out of a horror movie, but it’s a real and growing threat, and the way it spreads is depressingly familiar – weak, default, or reused passwords on internet-connected devices.

For a regional business owner, this story matters less because of the clever engineering behind it and more because of the door it walks through. Tengu isn’t breaking into fortified systems with some brilliant zero-day exploit. It’s walking in through the front door because nobody bothered to change the lock.

What Is Tengu, and Why Does It Matter to a Small Business?

Tengu is what’s known as a Mirai-derived botnet – built on the same family of malware that, a few years ago, was responsible for knocking large chunks of the internet offline by hijacking huge numbers of poorly secured devices. According to researchers at Nozomi Networks Labs, as reported by The Hacker News, Tengu spreads by brute-forcing Telnet logins on Linux-based devices – things like routers, network video recorders, IP cameras, and other small “always-on” gadgets that quietly sit on your network doing their job.

Once it’s in, Tengu doesn’t just sit there. It can be used to launch distributed denial-of-service (DDoS) attacks – essentially using your device’s internet connection, alongside thousands of others, to flood a target with traffic. Your business becomes an unwitting foot soldier in someone else’s attack, without you ever knowing it happened. And now, with its ability to force a reboot when defenders try to remove it, it’s even harder to clean up once it’s there.

How These Infections Actually Happen

The technical detail that should really grab your attention isn’t the reboot trick – it’s how the malware gets in to begin with. Telnet is an old, insecure way of remotely accessing a device, and it’s frequently left switched on by default on routers, cameras, NAS boxes, and other network hardware, often protected by nothing more than a factory-set username and password like “admin/admin”.

Most small businesses have several of these devices connected to their network without ever really thinking about them. A CCTV system installed five years ago. A cheap Wi-Fi extender bought online. An old modem sitting in a cupboard that nobody has logged into since the day it was installed. These are exactly the kind of devices Tengu and its predecessors are built to find.

Why This Is a Regional Business Problem, Not Just a “Big Tech” Problem

It’s tempting to assume stories like this are about large data centres and enterprise networks, but the opposite is true. Attackers running these botnets aren’t hand-picking high-value targets – they’re running automated scans across the entire internet, looking for any device, anywhere, with a weak login. A small accounting firm in Traralgon or a retail shop in Bairnsdale is just as visible to that scan as a company in Melbourne’s CBD.

In fact, smaller regional businesses can be more exposed, simply because they’re less likely to have dedicated IT staff keeping an inventory of every device on the network, checking firmware updates, or auditing what’s still running Telnet. It’s not a lack of care – it’s a lack of time and specialised knowledge, which is exactly the gap these automated attacks are designed to exploit.

The Real-World Consequences

Being caught up in a botnet like Tengu can cause more than just background noise on your network. Possible consequences include:

  • Your business internet connection becoming slow or unreliable as the device is used to send attack traffic
  • Your business IP address getting flagged or blacklisted by other services because it’s associated with malicious activity
  • Compromised devices being used as a stepping stone to reach other equipment on your network, including computers holding customer or financial data
  • Reputational risk if you’re a service provider and a client’s systems are affected through a shared connection

What You Can Actually Do About It

The good news is that defending against this kind of threat doesn’t require a big budget or deep technical expertise – it requires good habits, applied consistently. Here’s where to start:

  • Change every default password. Routers, cameras, NAS devices, printers – anything connected to your network should have a strong, unique password, not the one it shipped with.
  • Turn off Telnet and other remote access features you don’t use. If you’re not sure what’s switched on, that’s a sign it’s time for a proper network review.
  • Keep firmware updated. Device manufacturers regularly patch security flaws, but updates only help if they’re actually installed. Set a reminder to check, or better yet, have someone manage this for you.
  • Make a list of every device connected to your network. You can’t secure what you don’t know you have. Old cameras, forgotten modems, and unused equipment are prime targets.
  • Segment your network. Keep smart devices, cameras, and IoT equipment on a separate network from the computers handling sensitive business data, so a compromised device can’t easily reach everything else.
  • Retire genuinely outdated hardware. If a device is old enough that it no longer receives security updates from its manufacturer, it’s a liability, not a bargain.

The Bigger Picture

Tengu’s reboot trick is a genuinely clever piece of malware engineering, but it’s also a reminder of a much simpler truth: sophisticated attacks succeed because basic defences are missing. Most small businesses will never be targeted by a nation-state hacking group or a zero-day exploit written specifically for them. What they will face, almost inevitably, is automated malware scanning the entire internet for the easiest possible entry point – and a device with a default password is about as easy as it gets.

Taking an afternoon to audit the network devices sitting quietly in your office – the router in the server cupboard, the security camera above the till, the old modem nobody remembers plugging in – is one of the highest-value, lowest-cost security exercises a small business can do. It won’t stop every threat, but it removes exactly the kind of low-hanging fruit that botnets like Tengu are built to find.


Worried This Could Affect Your Business?

If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.

Book your free security assessment →

Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions