← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 7, 2026 · 14:12via Cyber Security News

New Linux Bot Hides as Kernel Process and Launches DDoS Attacks

Brief

A new Linux bot called Tengu is built to stay hidden and turn compromised systems into tools for disruption. The 32-bit malware poses as a routine kernel worker, persists across several Linux setups, and can generate traffic floods against selected targets.

Its broad feature set puts servers, embedded systems, and IoT-adjacent devices at risk. Unlike a simple denial-of-service tool, Tengu combines raw UDP and standard datagram floods with SSH handshake activity, web-request generation, and proxy features.

This gives operators several ways to consume bandwidth or application resources, while infected hosts can also be used to relay traffic. The analysis does not establish how victims are initially compromised, so its delivery route remains unconfirmed.

Read more on Cyber Security News