FortiGuard Labs has identified a new Linux backdoor named ClingSTUN. This malware converts compromised systems into proxies that utilize the Session Traversal Utilities for NAT (STUN) protocol. ClingSTUN functions as a back-connect proxy backdoor, enabling attackers to route traffic through infected machines.
ClingSTUN targets over two dozen vulnerabilities for initial system access, affecting devices from vendors such as Avtech, EnGenius, D-Link, Ivanti, and Realtek. The malware also contains a self-propagation mechanism with hardcoded exploits for seven additional vulnerabilities, including those in China Mobile and Linksys products. It supports various architectures, including AMD X86-64, ARM, and PowerPC, by fetching payloads via downloaders.
To maintain persistence, ClingSTUN copies itself to hidden files and appends startup commands to system initialization scripts. A notable feature is its abuse of legitimate public STUN servers to discover external IP addresses and port mappings, which helps maintain NAT connectivity without a separate coordination server. The malware establishes a UDP socket, binds to a random local port, and sends STUN binding requests.
FortiGuard Labs observed consistent behavior across three botnet variants, including killing competitor processes, terminating watchdog timers, and executing remote commands. The malware listens for specific packets to enable remote code execution and trigger its self-propagation. Defenders should monitor STUN activity, suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic to detect ClingSTUN infections.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
FortiGuard Labs discovered ClingSTUN, a Linux backdoor that transforms infected systems into proxies using the Session Traversal Utilities for NAT (STUN) protocol. The malware exploits dozens of vulnerabilities for initial access and includes a self-propagation mechanism, posing a threat to various network devices and Linux systems.