Security2 publishers2 min readPublished
ClingSTUN backdoor turns vulnerable Linux devices into proxies that check in through public STUN servers
FortiGuard Labs says the ClingSTUN Linux backdoor exploits two dozen flaws in a dozen vendors' gear and carries seven more to spread itself. Exploitation is indiscriminate, so any reachable vulnerable device on those lists, Ivanti's included, can join its proxy pool.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- The initial-access exploits hit Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda and TP-Link gear, and the operators appear to be adding more.
- Downloaders fetch ClingSTUN builds for x86-64, ARM, Intel 80386, MIPS R3000 and PowerPC processors.
- All three variants FortiGuard examined kill competitors' processes, terminate a watchdog timer, set up persistence and run remote commands.
- The backdoor copies itself into two hidden executable files and appends startup commands to three system initialization scripts.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint With no separate coordination server identified, the STUN channel offers no attacker-owned address to sinkhole, and denylisting the public STUN servers would hit legitimate services.
- cost Because the backdoor relaunches at every boot, a power cycle does not clean a device; each infection needs hands-on cleanup paid for by whoever owns the hardware.
- precedent Three variants sharing one core and an exploit set still growing point to an operation under active development, so later builds are likely to reach devices outside today's vendor lists.
ClingSTUN opens a UDP socket, binds it to a random local port and sends standard STUN binding requests [1]. The servers that answer are legitimate public STUN services [5]. FortiGuard Labs said the malware abuses them "to discover external IP addresses and port mappings, thereby helping maintain NAT connectivity" [5]. Then it keeps talking to them. "After completing the STUN binding exchanges, ClingSTUN periodically sends its group identifier and mapped-port list to the same STUN endpoints. No separate coordination-server registration was identified in this path," FortiGuard Labs said [3].
In the report, STUN does two jobs for a back-connect proxy: finding the device's public address and checking it in [4][3]. SecurityWeek's account does not say the proxied traffic itself travels inside STUN packets, and it does not give CVE identifiers, an infected-device count, first-seen dates, a patch deadline or the operators' identity [2].
FortiGuard's detection advice follows from that design. "These third-party services should not be automatically classified as attacker-controlled infrastructure. Instead, defenders should assess STUN activity alongside suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic," the lab said [11]. On a network, the pattern is a device with no use for STUN sending it on a timer, alongside a process its owner did not put there [3][11].
FortiGuard counts two dozen flaws used for initial access [4] and seven hardcoded into the propagation module, covering China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek and TBK devices [7]. The two lists add up to 31 exploits at most [13]. Realtek appears in both, so the number of distinct flaws may be lower [6][7].
Propagation starts on command. The malware listens for specific packets that let its operators execute code remotely and start the self-propagation routine [10]. Each infected device can then be turned against other vulnerable devices when the operators choose [10].
What to watch
- Publication of CVE identifiers for the exploited flaws, so owners can match them against specific device firmware versions.
- A fourth ClingSTUN variant adding exploits for vendors not on either current list.
- Any count of infected devices, or evidence of who is using the proxy capacity.