Security researchers have discovered a new piece of malware called Tengu that does something particularly stubborn: if you manage to kill the malicious process running on an infected device, it can trigger the device’s own hardware “watchdog” feature to force a reboot, giving the malware another chance to relaunch itself. It sounds like something out of a horror movie, but it’s a real and growing threat, and the way it spreads is depressingly familiar – weak, default, or reused passwords on internet-connected devices.
For a regional business owner, this story matters less because of the clever engineering behind it and more because of the door it walks through. Tengu isn’t breaking into fortified systems with some brilliant zero-day exploit. It’s walking in through the front door because nobody bothered to change the lock.
Tengu is what’s known as a Mirai-derived botnet – built on the same family of malware that, a few years ago, was responsible for knocking large chunks of the internet offline by hijacking huge numbers of poorly secured devices. According to researchers at Nozomi Networks Labs, as reported by The Hacker News, Tengu spreads by brute-forcing Telnet logins on Linux-based devices – things like routers, network video recorders, IP cameras, and other small “always-on” gadgets that quietly sit on your network doing their job.
Once it’s in, Tengu doesn’t just sit there. It can be used to launch distributed denial-of-service (DDoS) attacks – essentially using your device’s internet connection, alongside thousands of others, to flood a target with traffic. Your business becomes an unwitting foot soldier in someone else’s attack, without you ever knowing it happened. And now, with its ability to force a reboot when defenders try to remove it, it’s even harder to clean up once it’s there.
The technical detail that should really grab your attention isn’t the reboot trick – it’s how the malware gets in to begin with. Telnet is an old, insecure way of remotely accessing a device, and it’s frequently left switched on by default on routers, cameras, NAS boxes, and other network hardware, often protected by nothing more than a factory-set username and password like “admin/admin”.
Most small businesses have several of these devices connected to their network without ever really thinking about them. A CCTV system installed five years ago. A cheap Wi-Fi extender bought online. An old modem sitting in a cupboard that nobody has logged into since the day it was installed. These are exactly the kind of devices Tengu and its predecessors are built to find.
It’s tempting to assume stories like this are about large data centres and enterprise networks, but the opposite is true. Attackers running these botnets aren’t hand-picking high-value targets – they’re running automated scans across the entire internet, looking for any device, anywhere, with a weak login. A small accounting firm in Traralgon or a retail shop in Bairnsdale is just as visible to that scan as a company in Melbourne’s CBD.
In fact, smaller regional businesses can be more exposed, simply because they’re less likely to have dedicated IT staff keeping an inventory of every device on the network, checking firmware updates, or auditing what’s still running Telnet. It’s not a lack of care – it’s a lack of time and specialised knowledge, which is exactly the gap these automated attacks are designed to exploit.
Being caught up in a botnet like Tengu can cause more than just background noise on your network. Possible consequences include:
The good news is that defending against this kind of threat doesn’t require a big budget or deep technical expertise – it requires good habits, applied consistently. Here’s where to start:
Tengu’s reboot trick is a genuinely clever piece of malware engineering, but it’s also a reminder of a much simpler truth: sophisticated attacks succeed because basic defences are missing. Most small businesses will never be targeted by a nation-state hacking group or a zero-day exploit written specifically for them. What they will face, almost inevitably, is automated malware scanning the entire internet for the easiest possible entry point – and a device with a default password is about as easy as it gets.
Taking an afternoon to audit the network devices sitting quietly in your office – the router in the server cupboard, the security camera above the till, the old modem nobody remembers plugging in – is one of the highest-value, lowest-cost security exercises a small business can do. It won’t stop every threat, but it removes exactly the kind of low-hanging fruit that botnets like Tengu are built to find.
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.
(+61) 0412 440 804