Skip to content
Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

Securityweek •Ionut Arghire • October 5, 2026

A recently discovered Linux backdoor turns infected systems into proxies that use the Session Traversal Utilities for NAT (STUN) protocol and contains exploits for self-propagation, FortiGuard Labs reports.

Dubbed ClingSTUN and functioning as a back-connect proxy backdoor, the malware targets two dozen vulnerabilities for initial access and sets up persistence to ensure malware execution during the boot sequence.

The malware’s operators were seen indiscriminately exploiting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link flaws, and appear to be expanding their portfolio with other exploits as well.

Additionally, the backdoor includes a self-propagation mechanism containing hardcoded exploits for seven China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK vulnerabilities.

The ClingSTUN backdoor relies on downloaders to fetch malware payloads for different architectures, including AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC.

Across three variants of the botnet, FortiGuard Labs observed the same behavior related to killing competitors’ processes, terminating a watchdog timer, setting up the persistence mechanism, and executing remote commands.

For persistence, ClingSTUN copies itself to two hidden files with executable permissions, then appends startup commands to three system initialization scripts.

Additionally, it establishes a UDP socket, binds to a random local port, and sends standard STUN binding requests to set up endpoint connections.

“After completing the STUN binding exchanges, ClingSTUN periodically sends its group identifier and mapped-port list to the same STUN endpoints. No separate coordination-server registration was identified in this path,” FortiGuard Labs says.

The malware was also seen listening to specific packets that allow its operators to perform remote code execution and trigger the self-propagation mechanism.

“A notable feature is its abuse of legitimate public STUN servers to discover external IP addresses and port mappings, thereby helping maintain NAT connectivity. These third-party services should not be automatically classified as attacker-controlled infrastructure. Instead, defenders should assess STUN activity alongside suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic,” FortiGuard Labs notes.

Related: macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

Related: AI Agents Aimed SQL Injection at US and Canadian Government Sites

Related: Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

In Rare Move, Alleged Iranian State Hacker Extradited to US

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

Zammad Zero-Days Exploited in AI-Powered DIVD Hack

500,000 Active Credentials Left Exposed on GitHub

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

Alleged ShinyHunters Leader Arrested in Jordan

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

Fortra Patches Critical Vulnerabilities in BoKS

Flipboard Whatsapp Whatsapp Email

Extracted Entities

APT Groups (1)

Attack Types (1)

Domains (1)

Malware (1)

Platforms (3)

Vulnerabilities (1)