Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

https://www.securityweek.com/wp-content/uploads/2025/02/Linux-malware.jpeg

A recently discovered Linux backdoor turns infected systems into proxies that use the Session Traversal Utilities for NAT (STUN) protocol and contains exploits for self-propagation, FortiGuard Labs reports.

Dubbed ClingSTUN and functioning as a back-connect proxy backdoor, the malware targets two dozen vulnerabilities for initial access and sets up persistence to ensure malware execution during the boot sequence.

The malware’s operators were seen indiscriminately exploiting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link flaws, and appear to be expanding their portfolio with other exploits as well.

Additionally, the backdoor includes a self-propagation mechanism containing hardcoded exploits for seven China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK vulnerabilities.

The ClingSTUN backdoor relies on downloaders to fetch malware payloads for different architectures, including AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC.

Across three variants of the botnet, FortiGuard Labs observed the same behavior related to...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE