Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
BLUF
ClingSTUN malware targets Linux systems using STUN protocol abuse and dozens of exploits for covert persistence and propagation.
NEWS
Security researchers identified ClingSTUN as a back-connect proxy backdoor that disguises traffic via the STUN protocol. The malware contains exploits for dozens of flaws to enable self-propagation and establishes persistence mechanisms on compromised hosts. This campaign highlights the growing trend of abusing legitimate protocols for command and control.
Why I Care
Organizations running Linux servers face immediate risk of unauthorized access and lateral movement due to the malware's ability to bypass standard detection methods. The exploitation of dozens of flaws means many unpatched systems are vulnerable, potentially leading to data theft or ransomware deployment.
Next Steps
IT teams must patch all Linux systems against known vulnerabilities referenced in the advisory immediately. Security operations centers should update network monitoring to flag anomalous STUN traffic and scan endpoints for ClingSTUN indicators of compromise within 48 hours.
Source: Security Week ·