A new backdoor for Linux turns vulnerable internet-exposed devices into remote proxy nodes, using the public Session Traversal Utilities for NAT (STUN) to embed itself in regular VoIP and WebRTC traffic. FortiGuard said it has observed the malware, called ClingSTUN, in multiple attacks that exploit known vulnerabilities in routers, IoT devices, DVRs, and other network-connected devices.
See also: Dutch government develops its own Linux desktop based on NixOS

The malware has been observed exploiting vulnerabilities such as command injection, code injection and buffer overflows to gain initial access, with Fortinet noting that attackers are switching between different vulnerabilities and download sources as the campaign progresses. “A device doesn’t have to contain sensitive data to be useful to an attacker,” said Jason Soroko, senior researcher at Sectigo.
“ClingSTUN allows attackers to relay traffic through compromised devices and execute commands on them.” This makes the compromised device useful even when it is not a valuable target in itself. Fortinet described it as a “back-connect proxy backdoor” capable of maintaining persistence, executing remote commands, and spreading to other vulnerable devices.
Louis Eichenbaum, federal technology director at ColorTokens, said the campaign requires better countermeasure strategies. “When a vulnerable device cannot be patched immediately, defenders must be able to place compensating controls around it, limiting its exposure to the internet, restricting what it can communicate with, and closely monitoring its behavior until the vulnerability is resolved,” he said.
ClingSTUN was found to target a wide range of products, including Hytec routers, EnGenius IoT services, D-Link devices, TP-Link Archer AX21 routers, AVTECH cameras, and other equipment. The researchers said the malware currently has multiple known entry points and continues to evolve, with additional vulnerabilities being incorporated into the attack chain.
“ Updates take time to test and deploy, some functional and IoT devices cannot be easily disabled, and many legacy products are no longer supported by their manufacturers ,” Eichenbaum noted .
See also: File notification systems on Windows, Linux, Android leak user activity

“Attackers understand this reality and continue to target known vulnerabilities because these weaknesses remain effective.” Once installed, ClingSTUN takes steps to make removal and detection more difficult. It copies itself to hidden locations, adds entries to /etc/inittab, /etc/init.d/rcs, and /etc/rc.d/rc.boot to start at boot time, kills competing processes, and disables the watchdog timer.
It can also hide its process information by making its entry in “/proc” look like the system’s init process, the researchers said in a blog post. The malware also supports multiple Linux architectures, including ARM, Intel 80386, MIPS, PowerPC , and x86-64, allowing the same operation to target a wide range of embedded hardware.
Malware uses legitimate STUN traffic STUN is normally used to help applications discover their public IP address and port and establish connectivity through Network Address Translation (NAT). ClingSTUN abuses this infrastructure instead of using dedicated servers controlled by attackers. Fortinet observed the malware sending standard STUN connection requests to public endpoints, then periodically sending identifying information and mapped port data to these services.
The network security firm said the malware contains exploits for seven vulnerabilities that can be used to spread to additional devices. “The use of legitimate public STUN services shows why checking a destination’s reputation is not enough to judge whether traffic is safe,” Soroko said. “Security teams should investigate why a device is making these connections, rather than assuming that the service it’s communicating with is malicious or compromised.” The behavior of the device matters more than whether the destination appears on a block list, he noted.
See also: Linux kernel vulnerability allows access to ARM64 KVM Guests

For defenders, Fortinet recommends maintaining an accurate inventory of devices exposed to the internet, monitoring firmware and support status, applying available security updates, and isolating or replacing equipment that can no longer be repaired. Security teams should also look for suspicious processes, unexpected UDP connections, and repeated STUN traffic, along with the compromise indicators provided by Fortinet.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
