A newly documented Linux backdoor dubbed ClingSTUN is turning compromised systems into covert network proxies by abusing the Session Traversal Utilities for NAT (STUN) protocol and leveraging exploits for roughly two dozen vulnerabilities to spread across exposed devices.[1][5] Researchers at FortiGuard Labs detailed the malware’s behavior after observing it in the wild, warning that it combines back-connect proxy capabilities, aggressive exploitation of router and IoT flaws, and robust persistence mechanisms to survive reboots and maintain long-term footholds.[1][5]
According to the analysis, ClingSTUN operates as a back-connect proxy backdoor that establishes a UDP socket, binds to a random local port, and issues standard STUN binding requests to public STUN servers to discover its external IP address and mapped ports.[1][5][11] By doing so, it can traverse NAT and firewalls, turning infected hosts into relay nodes that proxy traffic on behalf of its operators while blending in with legitimate NAT-traversal activity.[1][5][7] FortiGuard notes that the malware periodically sends a group identifier and mapped-port list to the same STUN endpoints, enabling centralized tracking of infected machines without relying on obviously malicious command-and-control domains.[1][5] The researchers stress that these public STUN services themselves are legitimate and should not be automatically classified as attacker-controlled infrastructure.[1][5]
The campaign’s reach is amplified by ClingSTUN’s exploitation toolkit, which targets roughly two dozen vulnerabilities for initial access and embeds hardcoded exploits for seven bugs affecting China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK-branded devices.[1][5] Once a device is compromised, the backdoor relies on downloaders to retrieve architecture-specific payloads for AMD x86-64, ARM, Intel 80386, MIPS R3000, and PowerPC, reflecting a clear focus on heterogeneous IoT and embedded environments rather than traditional servers alone.[1] For persistence, ClingSTUN copies itself into hidden executable files and appends startup commands to multiple system initialization scripts, ensuring the malware launches automatically during the boot sequence.[1][5] The backdoor also listens for specially crafted packets that allow remote code execution and can trigger its self-propagation routine, turning each infected node into a stepping stone for further compromise.[1][5]
ClingSTUN’s reliance on STUN echoes a broader trend of malware families weaponizing NAT-traversal protocols, including the related “Cling” IoT botnet recently analyzed by Nozomi Networks.[3][6][8] That botnet was observed disguising its command-and-control traffic as replies from Google’s public STUN service, using repeated STUN binding requests with an all-zero transaction ID and embedding operator commands directly in STUN transaction fields to drive scanning, exploitation, tunneling, proxying, and denial-of-service attacks.[3][8] The Cling campaigns have been linked to exploitation of the Realtek Jungle SDK vulnerability CVE-2021-35394, which affects numerous consumer-grade routers and IoT devices and has been widely abused in botnet activity.[3][8] Together, these reports highlight how attackers increasingly hijack benign-looking STUN traffic to conceal both lateral movement and command channels behind patterns that resemble routine WebRTC or VoIP connectivity.[3][7][11]
For defenders, the ClingSTUN activity underscores the need to treat unusual STUN usage as a potential intrusion signal rather than background noise, particularly on devices that are not expected to run real-time communications workloads.[1][5][7] FortiGuard advises monitoring for repeated outbound STUN binding requests, unexpected UDP connections to public STUN servers, and recurring keepalive traffic originating from processes or paths that do not match legitimate applications on the host.[1][5] Network and security teams should also correlate suspicious STUN flows with indicators of compromise such as hidden executables, modified initialization scripts, and signs of unsolicited scanning or tunneling activity emanating from routers and IoT gear.[1][5][8]
Organizations operating Linux-based appliances, home or small-office routers, and other internet-exposed IoT devices should prioritize patching known vulnerabilities targeted by botnets, including Realtek Jungle SDK flaw CVE-2021-35394, and reduce direct exposure of management interfaces wherever possible.[3][8] Segmentation of untrusted devices, strict egress controls on UDP traffic, and baseline-aware monitoring of STUN usage can help limit the impact of backdoors like ClingSTUN, even when they piggyback on legitimate infrastructure.[1][5][7] Given the malware’s architectural flexibility and its focus on consumer and edge hardware, defenders are urged to expand visibility beyond traditional servers and endpoints to include the routers, cameras, and embedded systems that increasingly serve as high-value entry points into corporate and home networks.[1][5]
References
- Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
- Fortinet Blog – Broad, Integrated, Automated Cybersecurity
- Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
- Malware Trending: STUN Awareness
- Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
- RFC 3489: STUN – Simple Traversal of User Datagram …