A recently discovered Linux backdoor has been spotted using the Session Traversal Utilities for NAT (STUN) protocol to turn infected systems into proxies, exploiting dozens of vulnerabilities along the way. The malware, dubbed ClingSTUN, not only sets up a back-connect proxy backdoor but also contains self-propagation mechanisms that ensure its own execution during the boot sequence.
The operators behind ClingSTUN appear to be indiscriminate in their exploitation, targeting multiple vendors’ products and using hardcoded exploits for seven vulnerabilities in various networking equipment from companies such as China Mobile, KGUARD, Linksys, and Realtek. The malware also contains downloaders that fetch payloads for different architectures, including AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC.
Once installed, ClingSTUN establishes a UDP socket, binds to a random local port, and sends STUN binding requests to set up endpoint connections. The malware then periodically sends its group identifier and mapped-port list to the same STUN endpoints, allowing it to maintain NAT connectivity and potentially communicate with other infected systems. This behavior highlights the need for defenders to assess STUN activity alongside suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic.
One of the most concerning aspects of ClingSTUN is its ability to abuse legitimate public STUN servers to discover external IP addresses and port mappings. While these services should not be automatically classified as attacker-controlled infrastructure, they do provide a convenient means for malware operators to maintain connectivity with their compromised systems. This raises questions about the security posture of organizations that rely on these services.
The exploitation of multiple vulnerabilities by ClingSTUN’s operators also underscores the need for timely patching and vulnerability management. By targeting dozens of flaws in various networking equipment, the attackers have demonstrated a willingness to take advantage of known weaknesses rather than investing time in developing new exploits. This highlights the importance of maintaining up-to-date software and firmware across all systems, as well as implementing robust security measures to detect and prevent exploitation.
For users and administrators, this incident serves as a reminder to monitor system logs for suspicious activity related to STUN protocols and UDP connections. It also emphasizes the need for thorough vulnerability scanning and patching, particularly in environments where network equipment is exposed to the internet. By staying vigilant and proactive, organizations can reduce their exposure to attacks like ClingSTUN and minimize the risk of compromise.
Source: SecurityWeek — 2026-10-05