Historical intelligence backfill. This assessment covers reporting originally published on 2026-07-27 and was added to the RWP archive on 2026-09-07.
Tengu is Mirai that tries to stay — IoT persistence, not a plant-floor payload
Nozomi Labs 27 July 2026 — modern Mirai-derived family. Exposed embedded Linux still pays as DDoS node, proxy, and foothold. Incomplete features in the sample do not make it ICS malware.
Bottom line up front
CONFIRMED Nozomi Labs, 27 July 2026 — Tengu, a Mirai-derived IoT family whose point is persistence and reuse (DDoS, proxy, foothold) rather than a one-shot flood. Labs: some capabilities incomplete or unused in the sample; the lesson is still exposed embedded Linux. Not a PLC protocol implant. Distinct from Apex2/c2c (6 July) and from Aisuru (Bitsight). Process impact: UNKNOWN / not claimed. Plant-perimeter cameras, NVRs, and Linux RTUs remain the relevant asset class.
Historical backfill of 27 July 2026 reporting; added 7 September 2026.
What happened
Another Mirai grandchild with better manners about staying installed.
Why it mattered
Persistence on a camera VLAN is a beachhead. DDoS-for-hire is the monetization, not the only use.
Who / what was affected
Internet-facing IoT. No named industrial victim.
Technical context
Default creds, exposed services, no outbound allow-list. Same hygiene as the Go-botnet post.
Exploitation / threat status at the time
CONFIRMED Labs sample analysis.
UNKNOWN prevalence vs Aisuru/Mirai-main.
What defenders should have done
- Same IoT WAN closure as Apex2.
- Hunt persistence on embedded Linux (fake services, copied binaries).
- Do not merge Tengu IOCs into an ICS malware briefing.
RWP assessment
Confidence: High as a family note. Map to OT-IoT botnet cluster, not Sandworm.
Defensive actions
- Egress from camera/IoT VLANs.
- Credential rotation on embedded devices.
- Keep a botnet-family table so briefings do not collapse five names into one.
Sources
- Nozomi Networks Labs — Tengu — a modernized Mirai that doesn't want to leave
- Nozomi Networks Labs — Apex2 and c2c/meow Golang bots (same season)
- Bitsight — Aisuru botnet (separate family, Feb–June 2026 tracking)