FortiGuard Labs has published research on ClingSTUN, a Linux backdoor that turns compromised Internet-facing devices into proxy nodes. Fortinet says it spreads by exploiting known, unpatched vulnerabilities and uses public STUN servers to keep those devices reachable.

In its write-up, dated Oct. 5, FortiGuard Labs describes ClingSTUN as a back-connect proxy backdoor. It contacts public STUN servers to learn a device’s externally mapped IP address and port and to maintain NAT bindings. Many of those servers are legitimate public services, so the traffic blends with ordinary VoIP and WebRTC communications. Fortinet says it first saw delivery through CVE-2022-36553 in Hytec Inter HWL-2511-SS routers, then watched the operator move through three download sources and add entry points, among them flaws in EnGenius, D-Link, TP-Link, Ivanti Connect Secure and Tenda devices. The CVEs in its table run from 2019 to 2026, and Fortinet says the malware is still evolving.

On the host, Fortinet says the malware disables the device’s watchdog timer, kills processes it treats as competitors, and writes itself into boot scripts so the device runs it at startup. The post ends with lists of IP addresses and file hashes, and Fortinet says its IP reputation and anti-botnet service blocks the infrastructure tied to the campaign.

Our read: STUN is normal traffic on networks that carry voice and video, so blocking the protocol is not a realistic control. The controls Fortinet names are an accurate device inventory, prompt updates and less Internet exposure, and they apply here. The same pattern of many old flaws in one actor’s toolkit appears in One Threat Actor Weaponized Ten Unrelated CVEs. Fortinet also lists unsupported firmware among the gaps, and a device that no longer gets fixes belongs on the retire-or-isolate list, a case made in Replace an Exploited Edge Appliance Before You Trust It Again.

Source: FortiGuard Labs: ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure