www.securityweek.com 5 Oct 2026, 13:00 UTC

ClingSTUN Linux Backdoor Turns Infected Devices into STUN Proxies

ClingSTUN Linux Backdoor Turns Infected Devices into STUN Proxies

A newly discovered Linux backdoor, named ClingSTUN, converts infected hosts into proxies that abuse the Session Traversal Utilities for NAT (STUN) protocol. FortiGuard Labs reports that it uses a back‑connect proxy model, establishes persistence to survive reboots, and contains exploits for self‑propagation.

The operators have been seen exploiting around two dozen disclosed vulnerabilities across a range of vendors, including Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda and TP-Link, with indications they are expanding their exploit portfolio.

In addition, ClingSTUN includes a self‑propagation mechanism with hardcoded exploits for seven vendor families, notably China Mobile, KGUARD, Linksys, LB‑LINK, MVPower, Realtek and TBK, and it downloads payloads for architectures such as AMD X86‑64, ARM, Intel 80386, MIPS R3000 and PowerPC.

The malware operates through downloaders that fetch payloads, creates two hidden executable files for persistence, and appends startup commands to three system init scripts. It binds to a random UDP port and issues STUN binding requests to establish endpoint connections, periodically reporting its group identifier and mapped port list to the same endpoints. Observed activity includes listening for specific packets that trigger remote code execution and self‑propagation.

FortiGuard notes the abuse of legitimate public STUN servers to discover external IPs and port mappings; defenders should therefore assess STUN activity alongside suspicious process behaviour, unexpected UDP connections and recurring keepalive traffic, rather than automatically treating third‑party STUN services as attacker‑controlled infrastructure.

View full article

Article by CyberSIXT