ClingSTUN Backdoor Turns Linux Hosts Into Proxies
FortiGuard Labs details a Linux backdoor that abuses public STUN servers, exploits two dozen flaws, and self-propagates across routers.
Infected Linux systems are being quietly converted into back-connect proxies, according to research from FortiGuard Labs. The malware, tracked as ClingSTUN, leans on a protocol most networks already trust — the Session Traversal Utilities for NAT (STUN) — to maintain outbound connectivity while it hunts for new victims. The findings describe a backdoor that is part intrusion tool, part self-replicating worm, and part proxy service.
FortiGuard Labs reported that ClingSTUN targets two dozen vulnerabilities for initial access and sets up persistence so the malware executes during the boot sequence. The operators behind it were seen indiscriminately exploiting flaws in Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link devices, and appear to be expanding their portfolio with other exploits as well.
Two Dozen Flaws, One Backdoor
The initial-access phase is broad rather than targeted. According to FortiGuard Labs, ClingSTUN carries exploits for two dozen vulnerabilities, which the operators use against routers, access points, and other edge devices from a long list of vendors. Those vendors include Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link.
That roster mixes consumer-grade networking gear with industrial and enterprise equipment, which suggests the attackers are less interested in a specific victim profile than in volume. The report notes the operators appear to be expanding their portfolio with other exploits as well, meaning the initial-access toolkit is not static.
For defenders, the practical takeaway is that unpatched edge devices remain the entry point. The backdoor does not rely on a single novel vulnerability; it aggregates known flaws across many product lines.
Self-Propagation Built In
ClingSTUN does not wait for an operator to move laterally. The backdoor includes a self-propagation mechanism that contains hardcoded exploits for seven additional vulnerabilities, according to FortiGuard Labs. Those flaws affect China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK products.
That separation matters. The two dozen flaws used for initial access and the seven hardcoded exploits for propagation serve different roles in the infection chain. The propagation exploits are baked into the malware itself, allowing it to spread without a live operator issuing commands.
The result is a backdoor that can seed new infections on its own, provided it encounters a vulnerable target on the network. Combined with the broad vendor list, that creates conditions for rapid, indiscriminate spread across poorly maintained devices.
Downloaders and Architecture Coverage
The ClingSTUN backdoor relies on downloaders to fetch malware payloads tailored to different architectures, FortiGuard Labs reported. Those architectures include AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC.
That coverage spans the hardware commonly found in routers, embedded systems, and older Linux servers. By shipping architecture-specific payloads through downloaders, the malware can adapt to whatever host it lands on without carrying every binary in a single package.
Across three variants of the botnet, FortiGuard Labs observed the same behavior related to killing competitors' processes, terminating a watchdog timer, setting up the persistence mechanism, and executing remote commands. The consistency across variants points to a shared codebase that has been iterated rather than rebuilt from scratch.
Persistence Through Hidden Files
Once on a system, ClingSTUN takes steps to survive reboots. For persistence, it copies itself to two hidden files with executable permissions, then appends startup commands to three system initialization scripts.
That approach is straightforward but effective. Hidden files with executable permissions are easy to overlook during a casual inspection, and modifying three separate initialization scripts gives the malware multiple chances to relaunch if one path is cleaned.
The persistence routine is one of the behaviors observed consistently across the three botnet variants. It is also the step that turns a transient compromise into a durable foothold, which is why the report emphasizes boot-sequence execution.
STUN as a Cover Channel
The backdoor's most distinctive trait is its use of STUN. ClingSTUN establishes a UDP socket, binds to a random local port, and sends standard STUN binding requests to set up endpoint connections.
"After completing the STUN binding exchanges, ClingSTUN periodically sends its group identifier and mapped-port list to the same STUN endpoints. No separate coordination-server registration was identified in this path," FortiGuard Labs says.
That finding describes a command-and-control model that piggybacks on legitimate public STUN infrastructure rather than standing up dedicated servers. FortiGuard Labs also noted a broader implication for defenders.
"A notable feature is its abuse of legitimate public STUN servers to discover external IP addresses and port mappings, thereby helping maintain NAT connectivity. These third-party services should not be automatically classified as attacker-controlled infrastructure. Instead, defenders should assess STUN activity alongside suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic," FortiGuard Labs notes.
The warning cuts against a common reflex. Blocking or alerting on STUN traffic outright would generate noise and break legitimate applications, since STUN is widely used for NAT traversal in voice, video, and peer-to-peer services. The report instead recommends correlating STUN activity with other signals — process behavior, unexpected UDP connections, and recurring keepalive traffic.
ClingSTUN also listens for specific packets that allow its operators to perform remote code execution and trigger the self-propagation mechanism. That combination of listening, executing, and spreading means an infected host can act as both a proxy and a launch point for the next wave of infections.
What the Variants Share
The three botnet variants observed by FortiGuard Labs share a common behavioral core. They kill competitors' processes, terminate a watchdog timer, set up persistence, and execute remote commands.
Killing competing processes suggests the operators expect other malware to be present on the same devices, a common situation on exposed routers and embedded systems. Terminating a watchdog timer is a way to prevent the host from rebooting or resetting itself when the malware misbehaves.
Remote command execution is the payoff. Once persistence and connectivity are established, the operators can issue commands through the STUN-based channel and, when conditions allow, trigger self-propagation to expand the botnet.
Defender Signals to Watch
FortiGuard Labs' guidance points toward behavioral detection rather than simple blocklists. Defenders should treat ClingSTUN activity as a combination of indicators, not a single signature.
- ClingSTUN carries exploits for two dozen vulnerabilities for initial access, affecting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link products.
- Its self-propagation mechanism includes hardcoded exploits for seven vulnerabilities in China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK products.
- Downloaders fetch payloads for five architectures: AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC.
- FortiGuard Labs observed three variants of the botnet sharing the same core behaviors.
Those indicators span network and host. On the network side, unexpected UDP connections and recurring keepalive traffic to public STUN servers are worth correlating. On the host side, hidden executable files and modified initialization scripts are the persistence footprint to look for.
The report's emphasis on context is important. Because STUN is a legitimate protocol used by many applications, treating every STUN packet as malicious would be counterproductive. Instead, the recommendation is to assess STUN activity alongside suspicious process behavior and unexpected UDP connections.
Why This Matters for Edge Defenses
ClingSTUN highlights a persistent problem for organizations that depend on edge devices: the same hardware that provides connectivity often runs outdated firmware with known flaws. The backdoor's initial-access list reads like a catalog of vendors whose devices are frequently deployed and infrequently patched. When a single piece of malware carries exploits for two dozen vulnerabilities across that many product lines, patching one device category is not enough.
The self-propagation feature raises the stakes further. If a vulnerable device is reachable from an infected host, the malware can attempt to spread without a human operator. That could mean an infection that begins with one exposed router ends with several, particularly in environments where firmware updates lag.
The use of public STUN servers also complicates detection. Security teams that rely on blocking known malicious infrastructure may not see ClingSTUN's traffic as inherently suspicious, because it flows to services that legitimate applications use. This suggests defenders should invest in behavioral baselines for UDP traffic and keepalive patterns rather than depending solely on reputation-based blocking.
For readers managing Linux servers or edge devices, the practical implication is to treat firmware and patch status as an ongoing operational concern, not a one-time task. The report does not claim ClingSTUN is widespread, but its design — broad exploitation, self-propagation, and abuse of trusted infrastructure — is built for scale. Organizations that inventory their edge devices, monitor for anomalous STUN traffic, and watch for hidden executables and modified startup scripts will be better positioned to catch it early.
Sources
- SecurityWeek Original source
Continue Reading
Cling Botnet Hides Commands in STUN Traffic
New botnet abuses common STUN protocol and public servers to blend command-and-control with legitimate NAT-traversal activity.
RCE flaw in Rejetto HFS now exploited
Attackers are exploiting CVE-2026-61500 in Rejetto HFS to bypass authentication and gain remote code execution, according to VulnCheck.
China-Linked TA419 Hits US AI Policy Experts
Proofpoint attributes credential phishing targeting US AI policy experts to China-aligned TA419, which impersonated figures including an Anthropic employee.