📰
General 📅 2026-07-28 · 04:49 PM IST ⏱ 2 min read

Thousands of Servers Leaking Passwords While Hackers Deploy Unstoppable New Malware

Exposed computer management systems reveal security credentials, while new botnet resists removal attempts using hardware tricks.

A Growing Problem: Exposed Server Management Systems

Security researchers have discovered a troubling vulnerability affecting thousands of computers worldwide. Nearly 25,000 servers that manage physical hardware are openly accessible on the internet, and they're broadcasting sensitive password information to anyone who looks for it. These machines contain what's essentially the master keys to data centers and server rooms—and hackers are collecting them.

At the same time, a newly identified piece of malicious software called Tengu is making headlines for its unusual persistence. Unlike typical malware that can be defeated by simply shutting down a computer, Tengu has learned to use the machine's built-in safety mechanisms against defenders who try to remove it.

Understanding the Dual Threat

Think of server management systems like the control panels for a building's electrical system. They allow technicians to monitor, restart, and fix servers from anywhere in the world. The problem is that many organizations have left these panels accessible to the internet without proper passwords or protections—like leaving your house keys under the welcome mat.

When attackers access these exposed systems, they find password hashes—scrambled versions of login credentials. Modern computers use these hashes instead of storing plain passwords. However, attackers have tools that can crack these hashes through brute force, essentially guessing thousands of passwords per second until finding the right combination.

The Tengu botnet compounds this problem. Once installed on a computer, Tengu can recover from being shut down. Here's how: Every computer has a "watchdog" feature—a safety mechanism that automatically restarts the machine if it stops responding, like how your phone reboots if it freezes. Tengu weaponizes this feature. When a security team kills the malware's main process, the watchdog detects the problem and reboots the entire computer. When the system restarts, Tengu's backup copies activate and reload the malware before defenders can intervene.

Why This Matters to Everyone

Exposed server management systems threaten the infrastructure that runs the internet. Banks, email providers, streaming services, and cloud storage all depend on secure data centers. If attackers gain administrative access through compromised management systems, they can steal data, launch attacks, or simply shut down services entirely.

The Tengu botnet demonstrates how malware is becoming smarter. Traditional removal methods no longer work against sophisticated threats that understand and exploit hardware-level features.

What You Should Do Now

Organizations must recognize that server management systems are as critical as the locks on a bank vault—they deserve equal protection.

The combination of exposed credentials and resilient malware shows that cybersecurity requires constant vigilance and layered defenses.

📎 This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →