ClingSTUN Linux backdoor abuses STUN protocol, exploits dozens of flaws
FortiGuard Labs discovered a Linux backdoor dubbed ClingSTUN that turns infected systems into proxies using legitimate public STUN servers. The malware exploits roughly two dozen vulnerabilities in Avtech, D-Link, Ivanti, Realtek, TP-Link and other devices, and includes hardcoded exploits for self-propagation.
- Backdoor abuses public STUN servers to bypass NAT and maintain connectivity
- Exploits flaws in Avtech, D-Link, Ivanti, Realtek, Tenda, TP-Link and others
- Self-propagation via exploits for China Mobile, Linksys, LB-LINK, MVPower
- Persists via two hidden files and three system initialization scripts
Read next
Security