Critical Infrastructure Under Attack: 36,000 Exposed BMC Systems Reveal a Hidden Password Leak Risk While Tengu Botnet Expands Mirai’s Legacy + Video

Listen to this Post

Featured Image

Introduction: The Silent Exposure Inside Enterprise Hardware

Modern organizations invest heavily in endpoint security, firewalls, and cloud protection, but one of the most dangerous weaknesses often sits deeper inside the infrastructure: the hardware management layer. A recent cybersecurity investigation has revealed that more than 36,000 internet-exposed Baseboard Management Controller (BMC) systems were running Intelligent Platform Management Interface (IPMI), with nearly 25,000 systems exposing password hashes before authentication due to a decade-old vulnerability.

The discovery highlights a long-standing security problem: many organizations continue operating critical infrastructure components with outdated firmware, weak credentials, and insecure remote management configurations. At the same time, a new Mirai-derived botnet known as Tengu is targeting Linux devices, using advanced persistence techniques to keep infected systems online while launching large-scale attacks.

Together, these threats demonstrate how attackers continue exploiting overlooked systems. Whether through forgotten hardware interfaces or poorly protected internet-connected devices, the cybersecurity battlefield is increasingly shifting toward infrastructure that many defenders fail to monitor.

Thousands of BMC Systems Expose Password Hashes Through Old IPMI Vulnerability
A Decade-Old Flaw Still Putting Modern Infrastructure at Risk

Security researchers have discovered that approximately 36,000 internet-accessible BMC devices are still exposing vulnerable IPMI services. Nearly 25,000 of these systems reportedly leaked password hashes before authentication, creating an opportunity for attackers to steal and crack credentials offline.

The issue originates from CVE-2013-4786, a vulnerability affecting certain IPMI implementations. The flaw allows remote attackers to retrieve password hashes without successfully authenticating first. While the vulnerability was publicly documented more than a decade ago, many organizations have failed to patch, disable, or properly secure affected systems.

The persistence of this issue shows a recurring cybersecurity challenge: vulnerabilities do not disappear simply because patches exist. Legacy equipment, forgotten servers, and poorly maintained environments often remain exposed years after security fixes become available.

What Are BMC and IPMI Systems?

The Hidden Management Layer Behind Enterprise Servers

Baseboard Management Controllers are specialized chips built into servers and enterprise hardware. They allow administrators to remotely manage systems even when the operating system is offline or unavailable.

Through technologies such as IPMI, administrators can:

Restart servers remotely.

Monitor hardware health.

Access console functions.

Update firmware.

Diagnose failures.

These capabilities are extremely valuable for data centers and large organizations. However, when exposed directly to the internet, they become attractive targets for attackers.

A compromised BMC can provide deep access below the operating system level, making traditional security tools less effective.

Why Password Hash Exposure Creates Serious Risks

Offline Cracking Turns Weak Credentials Into Open Doors

Unlike normal password theft scenarios, leaked hashes allow attackers to perform offline cracking attacks. Instead of repeatedly trying passwords against a live system, criminals can use powerful hardware to test millions or billions of password combinations without detection.

Organizations using:

Default administrator passwords.

Factory credentials.

Weak password policies.

Shared management accounts.

are especially vulnerable.

Even strong-looking systems can become compromised if administrators never changed default credentials after deployment.

Enterprise Hardware Security Remains a Forgotten Battlefield

Attackers Are Moving Beyond Traditional Endpoints

For years, cybersecurity discussions have focused on laptops, workstations, phishing attacks, and malware. However, attackers increasingly target infrastructure components that defenders often overlook.

BMC devices represent an attractive target because they provide privileged access. A successful compromise could allow attackers to:

Install persistent malware.

Disable servers.

Modify firmware.

Access sensitive environments.

Maintain hidden control over infrastructure.

This type of access can become extremely valuable for espionage campaigns, ransomware operations, and supply-chain attacks.

Tengu Botnet: A New Generation of Mirai-Based Threats

Linux Devices Become Weapons Again

Alongside the BMC exposure discovery, researchers have identified Tengu, a Mirai-derived botnet targeting Linux systems.

Mirai became infamous after its 2016 attacks used compromised Internet of Things devices to create massive distributed denial-of-service campaigns. Since then, many botnets have evolved from its original codebase.

Tengu continues this tradition but introduces additional capabilities designed to improve persistence and flexibility.

Tengu Uses Watchdog Loops to Survive Removal Attempts

Malware That Refuses to Die

One of Tengu’s notable features is its ability to maintain persistence through watchdog reboot loops.

If security tools or administrators attempt to terminate the malicious process, Tengu can trigger mechanisms designed to restart infected components.

This makes removal more difficult because defenders are not simply fighting an active process — they are fighting malware designed to restore itself.

Persistence remains one of the biggest challenges in modern malware defense.

Multiple Attack Capabilities Make Tengu More Dangerous

From DDoS Attacks to Remote Control

Researchers report that Tengu supports approximately 25 different DDoS attack methods. This allows operators to adapt attacks depending on the target environment.

The botnet also includes capabilities such as:

SOCKS5 proxy functionality.

Remote command execution.

Payload downloading.

Device control operations.

These features transform infected Linux systems into flexible criminal infrastructure.

Rather than being limited to one purpose, modern botnets increasingly operate like underground platforms that can support multiple types of abuse.

The Connection Between BMC Exposure and Botnet Growth

Attackers Continue Searching for Weak Infrastructure

Although BMC vulnerabilities and botnets represent different attack categories, they share a common theme: exposed systems.

Attackers are constantly scanning the internet for:

Misconfigured services.

Weak authentication.

Outdated software.

Forgotten devices.

A vulnerable BMC could provide privileged access to enterprise servers, while compromised Linux devices can become part of a botnet army.

Both threats demonstrate the importance of reducing unnecessary exposure.

Deep Analysis: How Organizations Should Respond

Command 1: Audit Internet-Exposed Management Interfaces

Organizations should immediately identify whether BMC interfaces are accessible from the public internet.

Security teams should:

Scan external IP ranges.

Identify exposed IPMI services.

Remove unnecessary internet access.

Place management interfaces behind VPNs.

Remote management systems should rarely be directly reachable from the open internet.

Command 2: Eliminate Default Credentials

Default passwords remain one of the easiest attack paths.

Organizations should:

Change factory credentials immediately.

Use unique administrator passwords.

Enable multi-factor authentication where available.

Rotate privileged credentials regularly.

A vulnerable system with a strong password is far safer than a protected system using default credentials.

Command 3: Patch Legacy Infrastructure

Many organizations delay firmware updates because hardware maintenance can disrupt operations.

However, outdated firmware creates long-term security risks.

Security teams should establish:

Regular firmware review cycles.

Hardware vulnerability assessments.

Asset inventory management.

Retirement plans for unsupported equipment.

Command 4: Monitor for Botnet Activity

Linux servers and IoT devices should be continuously monitored for unusual behavior.

Warning signs include:

Unexpected outbound traffic.

Unknown processes.

Repeated process restarts.

Suspicious command execution.

Unauthorized proxy services.

Early detection can prevent devices from becoming part of larger criminal networks.

Command 5: Improve Infrastructure Visibility

Many cybersecurity incidents begin with organizations not knowing what they own.

Effective defense requires:

Complete asset inventories.

Network segmentation.

Vulnerability scanning.

Continuous monitoring.

Security teams cannot protect systems they cannot see.

What Undercode Say:

Infrastructure Security Is Becoming the Next Major Cyber Battlefield

The discovery of thousands of exposed BMC systems proves that attackers are increasingly targeting the foundation of digital environments rather than only user devices.

Old Vulnerabilities Continue Creating New Breaches

CVE-2013-4786 is more than a technical issue. It represents a larger failure in vulnerability management where organizations allow known weaknesses to remain active for years.

Hardware-Level Access Creates Extreme Risk

BMC compromise can bypass many traditional security controls because attackers gain access below the operating system layer.

Password Hash Leakage Should Never Be Ignored

Even encrypted password information can become dangerous when attackers have unlimited offline cracking time.

Default Credentials Remain One of Cybersecurity’s Biggest Problems

Despite decades of warnings, factory passwords continue enabling major compromises worldwide.

Internet Exposure Magnifies Small Mistakes

A system that is safe inside a protected network can become a major security risk when exposed publicly.

Mirai’s Evolution Shows Malware Adaptation

Tengu demonstrates how old malware families continue evolving with new persistence and control mechanisms.

Botnets Are Becoming More Flexible

Modern botnets are no longer limited to DDoS attacks. They increasingly provide access, proxy networks, and remote control capabilities.

Linux Systems Are Increasingly Targeted

As Linux becomes more common in servers, cloud environments, and IoT platforms, attackers are investing more resources into Linux-focused malware.

Cybersecurity Requires Continuous Maintenance

Security is not achieved by installing protection once. It requires constant updates, monitoring, and improvement.

✅ The BMC Exposure and IPMI Risk Are Technically Plausible

IPMI-related vulnerabilities, including CVE-2013-4786, have historically allowed password hash exposure in affected implementations. Weak passwords can potentially be cracked offline.

✅ Mirai-Derived Botnets Continue to Exist

Multiple malware families have evolved from Mirai’s original source code, targeting IoT and Linux-based systems with improved capabilities.

⚠️ Exact Numbers Require Independent Verification

The reported figures of 36,000 exposed BMC systems and 25,000 leaked hashes come from security research claims and should be confirmed through additional technical reporting.

Prediction

(-1) More Legacy Infrastructure Will Become a Target

As attackers continue scanning the internet, forgotten management interfaces and outdated hardware will likely become increasingly common entry points.

(-1) Credential-Based Attacks Will Increase

Password hash exposure combined with weak password practices will continue creating opportunities for unauthorized access.

(+1) Organizations Will Increase Hardware Security Awareness

Growing attacks against infrastructure components will push companies to improve asset visibility, segmentation, and remote management security.

(+1) Better Automated Detection Will Reduce Botnet Growth

Advanced monitoring tools and behavioral detection systems will make it harder for malware like Tengu to maintain long-term infections.

(-1) The Security Gap Between Modern and Legacy Systems Will Expand

Organizations running outdated infrastructure will face increasing risks as attackers develop more specialized tools against older technologies.

▶️ Related Video (68% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube