A new Linux backdoor, identified as ClingSTUN, is transforming infected computers into proxies by leveraging the Session Traversal Utilities for NAT (STUN) protocol, according to FortiGuard Labs. This malware includes exploits that facilitate its self-propagation.
Exploiting Multiple Vulnerabilities
ClingSTUN, functioning as a back-connect proxy backdoor, targets over twenty vulnerabilities to gain initial access, ensuring its persistence by modifying system startup sequences. The malware’s operators exploit flaws in devices from Avtech, EnGenius, D-Link, and others, while also expanding their arsenal of exploits.
In addition to exploiting existing vulnerabilities, the backdoor incorporates a self-propagation feature with hardcoded exploits for seven vulnerabilities in products from China Mobile, KGUARD, Linksys, and other manufacturers.
Technical Mechanisms and Architecture
The ClingSTUN malware utilizes downloaders to distribute payloads across various architectures, including AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC. FortiGuard Labs identified three botnet variants demonstrating consistent behaviors such as terminating rival processes and establishing persistence mechanisms.
To maintain its presence, ClingSTUN replicates itself into hidden executable files and adds startup commands to system initialization scripts. Furthermore, it employs a UDP socket binding process, sending standard STUN requests to establish endpoint connections.
Analysis and Defensive Measures
FortiGuard Labs reports that ClingSTUN does not require separate coordination-server registration, as it periodically updates its group identifier and mapped-port list with STUN endpoints. The malware listens for specific packets, allowing operators to execute remote commands and activate its self-propagation capabilities.
A key feature of ClingSTUN is its use of legitimate public STUN servers to determine external IP addresses and port mappings, enhancing NAT connectivity. Security experts advise that STUN activity should be assessed alongside any suspicious process behaviors and unexpected UDP connections to accurately identify threats.
Related cybersecurity developments include threats targeting macOS users, SQL injection attacks on government sites, and the use of AI agents in cyber threats. These incidents underline the ongoing need for vigilance in network security.
