ClingSTUN is a malicious Linux software that takes advantage of weaknesses in internet-connected devices, providing attackers with continual remote access. This sophisticated backdoor not only infects devices like routers and cameras but also transforms them into proxy nodes that can reroute traffic and execute commands remotely. The operation exploits known vulnerabilities in various vendor products, adapting its tactics as it progresses.
Exploiting IoT Device Vulnerabilities
Unpatched firmware, unsupported hardware, and exposed services are some of the vulnerabilities that ClingSTUN exploits to ensure infections persist through device reboots and evade detection. Researchers from Fortinet have identified three stages of this campaign, each utilizing distinct download sources to propagate the malware.
According to a report shared with Cyber Security News, the ClingSTUN operation involves exploiting vulnerabilities, ensuring startup persistence, and using public networking services to maintain control over compromised Linux devices. Although the threat is severe, the exact number of infections or a list of confirmed victims remains unreported.
Stages of the ClingSTUN Campaign
The initial stage of the campaign was detected using CVE-2022-36553, a command injection flaw in Hytec Inter HWL-2511-SS routers. This phase lasted only two days before the attackers diversified their methods and extended their reach to other vulnerable devices.
The second phase involved exploiting vulnerabilities in EnGenius cloud services and D-Link’s UPnP, among others. As the campaign evolved, more devices from manufacturers like Realtek, TP-Link, and AVTECH became targets, demonstrating the attackers’ strategy to leverage multiple entry points.
ClingSTUN’s downloader scripts are capable of supporting various systems, including ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64. The malware also removes certain process-related mounts and kills processes from temporary storage to establish its presence without interference.
Concealment and Persistence Techniques
ClingSTUN employs several techniques to conceal its operations. It clears command-line arguments, making it difficult to identify through standard process listings. When executed with admin privileges, it overlays its information with system metadata, mimicking legitimate processes.
The malware utilizes the STUN protocol, commonly used in internet calls, to discover external address mappings. The latest version contacted fewer public endpoints, requiring successful connections to each for remote command execution or self-propagation. The backdoor can also execute outbound TCP connections to receive further instructions.
Despite its capabilities, researchers have yet to determine how operators manage to obtain external mappings and deliver control traffic through network address translation. Public STUN servers should not be automatically deemed malicious but should be correlated with other suspicious activities.
Security Recommendations
Fortinet advises organizations to inventory internet-facing devices, ensure firmware is up-to-date, and promptly address exploited vulnerabilities. Unsupported devices should be replaced or isolated, and unnecessary services should be restricted. Monitoring for startup changes and unusual network behavior can help detect devices that have become persistent backdoors.
Indicators of compromise include specific campaign hosts, file hashes, and observed artifacts. Although these provide context for investigations, they are not confirmed as attacker-controlled infrastructure. Vigilance and proactive measures remain key in mitigating such sophisticated threats.
