Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
A sophisticated Linux backdoor has been discovered, infecting systems with malware that uses the Session Traversal Utilities for NAT (STUN) protocol to turn them into proxy servers. The malware, dubbed ClingSTUN, not only exploits two dozen vulnerabilities for initial access but also sets up persistence mechanisms to ensure its execution during the boot sequence.
The operators behind ClingSTUN appear to be indiscriminately exploiting flaws in a wide range of products from various manufacturers, including Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link. Moreover, the backdoor includes a self-propagation mechanism containing hardcoded exploits for seven China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK vulnerabilities.
To propagate itself, ClingSTUN relies on downloaders to fetch malware payloads for different architectures, including AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC. This allows the operators to infect a wide range of systems, making it challenging for defenders to contain the threat.
The malware’s behavior was observed across three variants of the botnet, which showed similar patterns related to killing competitors’ processes, terminating watchdog timers, setting up persistence mechanisms, and executing remote commands. ClingSTUN achieves persistence by copying itself to two hidden files with executable permissions and appending startup commands to three system initialization scripts.
To set up endpoint connections, the malware establishes a UDP socket, binds to a random local port, and sends standard STUN binding requests. After completing these exchanges, ClingSTUN periodically sends its group identifier and mapped-port list to the same STUN endpoints. This behavior highlights the abuse of legitimate public STUN servers by the operators to discover external IP addresses and port mappings.
The discovery of ClingSTUN raises concerns about the potential for attackers to use legitimate services as a means of maintaining control over compromised systems. Defenders should be aware that STUN activity, combined with suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic, can indicate malicious activity.
For system administrators and defenders, this incident serves as a reminder to regularly monitor their systems for signs of compromise, such as unusual network activity or the presence of unknown processes. Implementing robust security measures, including regular software updates, vulnerability assessments, and intrusion detection systems, can help mitigate the risk of infection by ClingSTUN and similar threats.
As the threat landscape continues to evolve, it is essential for defenders to stay vigilant and adapt their strategies to address emerging threats like ClingSTUN. By doing so, they can protect their organizations from falling victim to sophisticated malware attacks that exploit multiple vulnerabilities and abuse legitimate protocols.
Source: SecurityWeek — 2026-10-05