What happened
Security researchers at Nozomi Networks Labs have documented a Mirai-derived botnet named Tengu that exploits a Linux device's built-in hardware watchdog timer to force a reboot when defenders terminate its primary process — giving the malware's secondary persistence mechanisms a fresh opportunity to reinstall itself. The botnet propagates via Telnet brute-force attacks and supports at least 25 distinct DDoS attack methods. Separately, LG Electronics USA announced it will suspend smart TV applications on its webOS platform that have been found routing internet traffic through users' televisions as residential proxy nodes, following researcher findings that more than 42 percent of apps in LG's store facilitate this practice for unknown third parties.
Why it matters for your business
Tengu's watchdog abuse represents a meaningful escalation in botnet resilience: simply killing a malicious process is no longer sufficient to neutralize an infection on Linux-based edge devices, routers, or embedded systems. Operations and security teams should audit their Linux fleets for unauthorized watchdog configurations and implement network-level controls that detect anomalous Telnet exposure. The LG situation underscores that consumer hardware sitting on corporate guest networks or in home offices used by remote employees can quietly become an exit node for criminal proxy infrastructure — a risk that traditional endpoint security tools will never see. Procurement and IT policy should account for smart TV and IoT device vetting, particularly when those devices connect to any network that touches company resources.
What to watch next
Tengu's 25 DDoS vectors suggest the operators are positioning it as a for-hire attack platform, so organizations should monitor threat-intelligence feeds for campaigns linked to the botnet and validate their DDoS mitigation posture accordingly. On the LG front, the effectiveness of the app-store ban will depend heavily on enforcement rigor and whether developers simply repackage proxy functionality under different permissions — regulators and platform-accountability advocates are likely to scrutinize the outcome closely.
