Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Open or closed AI? Learn what to build on at Disrupt 2026

    October 5, 2026

    Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

    October 5, 2026

    Coinbase says AI support tests fell from weeks to minutes

    October 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Open or closed AI? Learn what to build on at Disrupt 2026
    • Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
    • Coinbase says AI support tests fell from weeks to minutes
    • Astronomers say they’ve spotted the first miniature quasar pointed at Earth
    • Wisconsin’s controversial anti-union law faces a reckoning this fall. Here’s what that could mean.
    • To state school alumni starting university, I say this: be proud of your background | Rhiannon Lucy Cosslett
    • Teenager’s hand blown off during confrontation between France school protesters and riot police
    • The full Disrupt Stage lineup
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, October 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 5, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A recently discovered Linux backdoor turns infected systems into proxies that use the Session Traversal Utilities for NAT (STUN) protocol and contains exploits for self-propagation, FortiGuard Labs reports.

    Dubbed ClingSTUN and functioning as a back-connect proxy backdoor, the malware targets two dozen vulnerabilities for initial access and sets up persistence to ensure malware execution during the boot sequence.

    The malware’s operators were seen indiscriminately exploiting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link flaws, and appear to be expanding their portfolio with other exploits as well.

    Additionally, the backdoor includes a self-propagation mechanism containing hardcoded exploits for seven China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK vulnerabilities.

    The ClingSTUN backdoor relies on downloaders to fetch malware payloads for different architectures, including AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC.

    Across three variants of the botnet, FortiGuard Labs observed the same behavior related to killing competitors’ processes, terminating a watchdog timer, setting up the persistence mechanism, and executing remote commands.

    Advertisement. Scroll to continue reading.

    For persistence, ClingSTUN copies itself to two hidden files with executable permissions, then appends startup commands to three system initialization scripts.

    Additionally, it establishes a UDP socket, binds to a random local port, and sends standard STUN binding requests to set up endpoint connections.

    “After completing the STUN binding exchanges, ClingSTUN periodically sends its group identifier and mapped-port list to the same STUN endpoints. No separate coordination-server registration was identified in this path,” FortiGuard Labs says.

    The malware was also seen listening to specific packets that allow its operators to perform remote code execution and trigger the self-propagation mechanism.

    “A notable feature is its abuse of legitimate public STUN servers to discover external IP addresses and port mappings, thereby helping maintain NAT connectivity. These third-party services should not be automatically classified as attacker-controlled infrastructure. Instead, defenders should assess STUN activity alongside suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic,” FortiGuard Labs notes.

    Related: macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    Related: AI Agents Aimed SQL Injection at US and Canadian Government Sites

    Related: Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

    Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

    Abuses Backdoor Dozens exploits flaws Linux Protocol STUN
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

    250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

    Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 

    Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

    Google halts open-source bug bounty program amid AI spam surge

    Alleged ShinyHunters Leader Arrested in Jordan

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Open or closed AI? Learn what to build on at Disrupt 2026

    October 5, 2026

    Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

    October 5, 2026

    Coinbase says AI support tests fell from weeks to minutes

    October 5, 2026

    Astronomers say they’ve spotted the first miniature quasar pointed at Earth

    October 5, 2026
    Latest Posts

    What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience

    August 9, 2026

    Britain is paying the price for failing to invest in its young people | Richard Partington

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Open or closed AI? Learn what to build on at Disrupt 2026

    October 5, 2026

    Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

    October 5, 2026

    Coinbase says AI support tests fell from weeks to minutes

    October 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.