ClingSTUN Linux backdoor abuses STUN, exploits 24 flaws
A newly identified Linux backdoor called ClingSTUN turns compromised systems into proxies and uses the Session Traversal Utilities for NAT (STUN) protocol to stay reachable, according to FortiGuard Labs. The malware also carries its own exploits, which let it spread to other devices.
STUN is a standard protocol that helps devices sitting behind network address translation (NAT) learn their public IP address and port mappings. ClingSTUN uses this capability to keep infected machines connected to its operators.
Two dozen flaws for initial access
FortiGuard Labs describes ClingSTUN as a back-connect proxy backdoor. To get onto systems, it targets two dozen vulnerabilities. Once installed, it sets up persistence so that it runs again during the boot sequence.
The operators have been exploiting flaws indiscriminately, rather than going after specific victims. Affected vendors include Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link. The researchers say the group appears to be adding more exploits to this list.
ClingSTUN also has a separate self-propagation mechanism. This component contains hardcoded exploits for seven vulnerabilities in products from China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK.
Built for many architectures
The backdoor depends on downloaders that fetch payloads compiled for different processor architectures. FortiGuard Labs lists AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC among the supported targets.
The researchers analyzed three variants of the botnet and found the same core behavior in each. The malware kills processes belonging to competing malware, terminates a watchdog timer, sets up persistence, and executes remote commands.
To survive reboots, ClingSTUN copies itself to two hidden files and gives them executable permissions. It then appends startup commands to three system initialization scripts.
How the STUN trick works
For networking, the malware creates a UDP socket, binds it to a random local port, and sends standard STUN binding requests to set up endpoint connections.
"After completing the STUN binding exchanges, ClingSTUN periodically sends its group identifier and mapped-port list to the same STUN endpoints. No separate coordination-server registration was identified in this path," FortiGuard Labs explained.
The backdoor also listens for specific packets. These let its operators run code remotely and start the self-propagation routine.
The researchers stressed that the STUN servers involved are legitimate public services, which complicates detection.
"A notable feature is its abuse of legitimate public STUN servers to discover external IP addresses and port mappings, thereby helping maintain NAT connectivity. These third-party services should not be automatically classified as attacker-controlled infrastructure. Instead, defenders should assess STUN activity alongside suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic," the researchers noted.
Our Take
ClingSTUN fits a familiar pattern. Linux botnets build their reach on routers, cameras, DVRs, and other network gear that is rarely patched and often forgotten once installed. The vendor list here is long, and the operators are said to be adding exploits. This suggests a group that cares more about volume than precision. Any exposed device with a known, unpatched bug is a candidate. This approach benefits from the steady growth in published flaws, a trend we covered when vulnerability disclosures doubled and exploitation sped up.
The more interesting part is the use of public STUN servers. By relying on legitimate infrastructure for NAT traversal, the operators avoid an obvious command-and-control server that defenders could block. FortiGuard Labs found no separate coordination-server registration in the path it analyzed. That makes simple blocklists less useful. Blocking public STUN services outright could also break legitimate real-time communication tools. The same idea of hiding malicious activity inside trusted services shows up elsewhere, for example in the CloudSyncD macOS backdoor that disguised itself as a Zoom installer.
For administrators, the practical steps are straightforward. Inventory internet-facing embedded devices, patch or replace those from the affected vendors, and watch for STUN traffic from systems that have no reason to generate it. Recurring keepalive patterns and unexpected UDP connections are useful signals, as the researchers point out.
It is worth watching whether other botnet families copy this STUN-based approach. It is also worth watching how quickly ClingSTUN's exploit list keeps growing.
