Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Linux Malware Exploits STUN Protocol, Targets Flaws

Linux Malware Exploits STUN Protocol, Targets Flaws

Posted on October 5, 2026 By CWS

A new Linux backdoor, identified as ClingSTUN, is transforming infected computers into proxies by leveraging the Session Traversal Utilities for NAT (STUN) protocol, according to FortiGuard Labs. This malware includes exploits that facilitate its self-propagation.

Exploiting Multiple Vulnerabilities

ClingSTUN, functioning as a back-connect proxy backdoor, targets over twenty vulnerabilities to gain initial access, ensuring its persistence by modifying system startup sequences. The malware’s operators exploit flaws in devices from Avtech, EnGenius, D-Link, and others, while also expanding their arsenal of exploits.

In addition to exploiting existing vulnerabilities, the backdoor incorporates a self-propagation feature with hardcoded exploits for seven vulnerabilities in products from China Mobile, KGUARD, Linksys, and other manufacturers.

Technical Mechanisms and Architecture

The ClingSTUN malware utilizes downloaders to distribute payloads across various architectures, including AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC. FortiGuard Labs identified three botnet variants demonstrating consistent behaviors such as terminating rival processes and establishing persistence mechanisms.

To maintain its presence, ClingSTUN replicates itself into hidden executable files and adds startup commands to system initialization scripts. Furthermore, it employs a UDP socket binding process, sending standard STUN requests to establish endpoint connections.

Analysis and Defensive Measures

FortiGuard Labs reports that ClingSTUN does not require separate coordination-server registration, as it periodically updates its group identifier and mapped-port list with STUN endpoints. The malware listens for specific packets, allowing operators to execute remote commands and activate its self-propagation capabilities.

A key feature of ClingSTUN is its use of legitimate public STUN servers to determine external IP addresses and port mappings, enhancing NAT connectivity. Security experts advise that STUN activity should be assessed alongside any suspicious process behaviors and unexpected UDP connections to accurately identify threats.

Related cybersecurity developments include threats targeting macOS users, SQL injection attacks on government sites, and the use of AI agents in cyber threats. These incidents underline the ongoing need for vigilance in network security.

Security Week News Tags:Backdoor, cyber threat, Cybersecurity, Exploits, FortiGuard Labs, Linux, Malware, network security, STUN protocol, Vulnerabilities

Post navigation

Previous Post: Rising Credential Layer Challenges Security Teams
Next Post: Denmark’s Massive Data Breach: 8.8 Million Records Compromised

Related Posts

Security Firm Andy Frain Says 100,000 People Impacted by Ransomware Attack Security Firm Andy Frain Says 100,000 People Impacted by Ransomware Attack Security Week News
Flaw Allowing Website Takeover Found in WordPress Plugin With 400k Installations Flaw Allowing Website Takeover Found in WordPress Plugin With 400k Installations Security Week News
Qualcomm Flags Exploitation of Adreno GPU Flaws, Urges OEMs to Patch Urgently Qualcomm Flags Exploitation of Adreno GPU Flaws, Urges OEMs to Patch Urgently Security Week News
The UK Brings Cyberwarfare Out of the Closet The UK Brings Cyberwarfare Out of the Closet Security Week News
Zero Trust Model’s Relevance in the Age of AI Zero Trust Model’s Relevance in the Age of AI Security Week News
Critical Vulnerability Patched in SAP NetWeaver Critical Vulnerability Patched in SAP NetWeaver Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Senate Approves Bill to Enhance Healthcare Cybersecurity
  • Weekly Cybersecurity Update: NetScaler, FortiMail Flaws
  • Citrix NetScaler Vulnerability Urgently Addressed by CISA
  • Google Adjusts Bug Bounty Amid Surge of Invalid Reports
  • Realtek SDK Flaw Exploited for Cling Botnet Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Senate Approves Bill to Enhance Healthcare Cybersecurity
  • Weekly Cybersecurity Update: NetScaler, FortiMail Flaws
  • Citrix NetScaler Vulnerability Urgently Addressed by CISA
  • Google Adjusts Bug Bounty Amid Surge of Invalid Reports
  • Realtek SDK Flaw Exploited for Cling Botnet Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark