Securityweek ClingSTUN Linux Backdoor Exploits STUN Protocol and Multiple Vulnerabilities
Article Content
- •ClingSTUN exploits over 24 vulnerabilities in IoT devices for remote access.
- •It uses the STUN protocol to maintain connectivity and evade detection.
- •Organizations are advised to enhance their cybersecurity practices to prevent infections.
The ClingSTUN backdoor has been identified as a Linux malware that exploits numerous vulnerabilities in Internet-facing devices, turning them into proxy nodes for remote attackers. It targets flaws in devices from manufacturers like D-Link, TP-Link, and Realtek, utilizing the STUN protocol for NAT traversal to maintain connectivity. The malware exploits at least 24 vulnerabilities for initial access and includes a self-propagation mechanism with hardcoded exploits for additional vulnerabilities. ClingSTUN establishes persistence by copying itself to hidden files and modifying system initialization scripts. The malware's traffic blends with legitimate STUN server communications, complicating detection efforts. Organizations are urged to improve their cybersecurity hygiene by applying security updates and limiting Internet exposure to mitigate risks. FortiGuard Labs has been monitoring this threat closely, emphasizing the importance of maintaining an accurate device inventory.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track ClingSTUN, Realtek and CVE-2021-35394 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What devices are affected by ClingSTUN?
How does ClingSTUN maintain connectivity?
What actions should organizations take?
Continue Reading
Cling Botnet Exploits Realtek Jungle SDK Vulnerability Threat actors are exploiting a critical vulnerability (CVE-2021-35394) in the Realtek Jungle SDK to deploy a botnet malware named Cling. This malware utilizes STUN traffic to create a covert command-and-control channel, allowing it to blend in with legitimate network activity. The vulnerability, which has a CVSS score…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…