Skip to main content

Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

0
High
Malwarelinux
Published: 10/05/2026 (10/05/2026, 13:00:00 UTC)
Source: SecurityWeek

Description

ClingSTUN is a Linux backdoor malware that operates as a back-connect proxy using the STUN protocol. It sets up persistence on infected systems and exploits multiple vulnerabilities across various device vendors for initial access and self-propagation. The malware abuses legitimate public STUN servers to maintain NAT connectivity and avoid direct attacker infrastructure. It targets a wide range of vulnerabilities in devices from vendors such as Avtech, EnGenius, D-Link, and others, and supports multiple CPU architectures. ClingSTUN also kills competing malware processes and listens for specific packets to execute remote commands and propagate further.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/05/2026, 13:03:26 UTC

Technical Analysis

ClingSTUN is a Linux backdoor that functions as a back-connect proxy by abusing the Session Traversal Utilities for NAT (STUN) protocol to maintain network connectivity through NAT devices. It establishes persistence by copying itself to hidden executable files and modifying system initialization scripts to run on boot. The malware exploits dozens of known vulnerabilities across multiple device vendors for initial infection and self-propagation, including hardcoded exploits for seven additional vulnerabilities in devices from China Mobile, KGUARD, Linksys, and others. It supports multiple CPU architectures (AMD X86-64, ARM, Intel 80386, MIPS R3000, PowerPC) and includes functionality to kill competing malware processes and terminate watchdog timers. ClingSTUN communicates with public STUN servers to discover external IP addresses and port mappings, avoiding direct use of attacker-controlled infrastructure. It listens for specific network packets to enable remote code execution and trigger propagation mechanisms.

Potential Impact

The malware compromises Linux systems by establishing a persistent backdoor that turns infected hosts into proxies, enabling attackers to route traffic through them. It exploits numerous vulnerabilities in network devices and software to gain initial access and propagate, potentially expanding its reach. The use of legitimate STUN servers for NAT traversal complicates detection and attribution. The backdoor's ability to execute remote commands and kill competing malware increases its control over infected systems and persistence. This can lead to unauthorized access, lateral movement, and further compromise within affected networks.

Defensive Guidance

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Defenders should monitor for unusual STUN protocol activity combined with suspicious processes, unexpected UDP connections, and recurring keepalive traffic. Since ClingSTUN abuses legitimate public STUN servers, detection should not rely solely on identifying STUN traffic but on correlating it with other malicious behaviors. Network segmentation and restricting outbound UDP traffic where feasible may help reduce exposure. Investigate and remediate known vulnerabilities in affected devices from the listed vendors to reduce initial infection vectors.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.72,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/linux-backdoor-abuses-stun-protocol-exploits-dozens-of-flaws/","fetched":true,"fetchedAt":"2026-10-05T13:03:19.774Z","wordCount":1019}

Threat ID: 6ac3a0192cdf04f656009343

Added to database: 10/05/2026, 13:03:21 UTC

Last enriched: 10/05/2026, 13:03:26 UTC

Last updated: 10/05/2026, 19:03:21 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses