← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

ClingSTUN Linux Backdoor Exploits Dozens of Flaws and Uses STUN Protocol for Proxies

🔄 Updated 52m ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • ClingSTUN is a Linux backdoor that creates back-connect proxies.
  • It exploits over two dozen vulnerabilities for initial access and self-propagation.
  • The malware uses the STUN protocol to maintain NAT connectivity.
  • ClingSTUN establishes persistence and targets multiple architectures.

New Linux Backdoor Discovered

FortiGuard Labs has identified a new Linux backdoor named ClingSTUN. This malware converts compromised systems into proxies that utilize the Session Traversal Utilities for NAT (STUN) protocol. ClingSTUN functions as a back-connect proxy backdoor, enabling attackers to route traffic through infected machines.

Exploitation and Self-Propagation

ClingSTUN targets over two dozen vulnerabilities for initial system access, affecting devices from vendors such as Avtech, EnGenius, D-Link, Ivanti, and Realtek. The malware also contains a self-propagation mechanism with hardcoded exploits for seven additional vulnerabilities, including those in China Mobile and Linksys products. It supports various architectures, including AMD X86-64, ARM, and PowerPC, by fetching payloads via downloaders.

Persistence and STUN Protocol Abuse

To maintain persistence, ClingSTUN copies itself to hidden files and appends startup commands to system initialization scripts. A notable feature is its abuse of legitimate public STUN servers to discover external IP addresses and port mappings, which helps maintain NAT connectivity without a separate coordination server. The malware establishes a UDP socket, binds to a random local port, and sends STUN binding requests.

Operational Behavior and Detection

FortiGuard Labs observed consistent behavior across three botnet variants, including killing competitor processes, terminating watchdog timers, and executing remote commands. The malware listens for specific packets to enable remote code execution and trigger its self-propagation. Defenders should monitor STUN activity, suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic to detect ClingSTUN infections.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 05

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

FortiGuard Labs discovered ClingSTUN, a Linux backdoor that transforms infected systems into proxies using the Session Traversal Utilities for NAT (STUN) protocol. The malware exploits dozens of vulnerabilities for initial access and includes a self-propagation mechanism, posing a threat to various network devices and Linux systems.