WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Gloved hands sliding a hardware module into a server rackAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure, according to Security Affairs. Fortinet details ClingSTUN, a Linux backdoor (a hidden way into a system that bypasses its login) exploiting unpatched IoT (everyday devices connected to a network) devices and abusing public STUN servers to route traffic past NAT. FortiGuard Labs researchers spotted a Linux malware (software written to damage a system or steal from it) family they call ClingSTUN, and the name gives away its trick immediately.

Instead of relying on a dedicated command server, the malicious code leans on STUN, the protocol that helps devices behind a router figure out their real public IP address. Video calling apps use it constantly, which means ClingSTUN’s network traffic hides inside something that already looks completely normal. “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes. It abuses public STUN (Session Traversal Utilities for NAT) infrastructure to discover externally mapped IP addresses and ports, maintain NAT bindings, and improve connectivity between compromised hosts and remote operators.”

Sources & evidence