FortiGuard Labs uncovered ClingSTUN, a Linux backdoor that turns infected devices into STUN-based proxies and includes exploits for self-propagation across many vulnerable products. It also uses persistence, architecture-specific payloads, and remote command capabilities while abusing legitimate public STUN servers for NAT connectivity. #ClingSTUN #FortiGuardLabs #STUN #Avtech #EnGenius #DLink #Ivanti #TPLink
Keypoints
- ClingSTUN is a Linux backdoor that functions as a back-connect proxy.
- It targets about two dozen vulnerabilities for initial access.
- The malware includes hardcoded exploits for self-propagation.
- It supports multiple architectures, including AMD X86-64, ARM, MIPS, and PowerPC.
- ClingSTUN uses STUN traffic, persistence scripts, and remote commands to maintain control.
Read More: https://www.securityweek.com/linux-backdoor-abuses-stun-protocol-exploits-dozens-of-flaws/