{"id":9918,"date":"2026-10-06T11:49:58","date_gmt":"2026-10-06T11:49:58","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9918"},"modified":"2026-10-06T11:49:58","modified_gmt":"2026-10-06T11:49:58","slug":"new-linux-malware-turns-vulnerable-iot-devices-into-proxy-nodes","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9918","title":{"rendered":"New Linux malware turns vulnerable IoT devices into proxy nodes"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A new Linux backdoor is turning vulnerable internet-facing devices into remotely controlled proxy nodes, while using the public Session Traversal Utilities for <a href=\"https:\/\/www.csoonline.com\/article\/4206299\/natjack-exploits-put-nat-security-assumptions-to-the-test-at-black-hat-2.html\" target=\"_blank\" rel=\"noopener\">NAT<\/a> (STUN) infrastructure to blend into normal VoIP and WebRTC traffic.<\/p>\n<p class=\"wp-block-paragraph\">Fortinet\u2019s FortiGuard Labs said it has been tracking the malware, dubbed ClingSTUN, across multiple attacks exploiting known vulnerabilities in routers, IoT devices, DVRs and other network-connected hardware.<\/p>\n<p class=\"wp-block-paragraph\">The malware was seen exploiting flaws including command injection, code injection, and <a href=\"https:\/\/www.csoonline.com\/article\/3823937\/cisa-fbi-call-software-with-buffer-overflow-issues-unforgivable.html\">buffer overflows<\/a> to gain an initial foothold, with Fortinet observing attackers switch between different vulnerabilities and download sources as the campaign evolved.<\/p>\n<p class=\"wp-block-paragraph\">\u201cA device does not need to hold sensitive data to be useful to an attacker,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/jason-soroko-19b41920\/\" target=\"_blank\" rel=\"noopener\">Jason Soroko<\/a>, senior fellow at Sectigo. \u201cClingSTUN lets attackers relay traffic through compromised devices and run commands on them.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That makes the compromised device useful even when it is not itself a valuable target. Fortinet described it as a \u201cback-connect proxy backdoor\u201d capable of maintaining persistence, executing remote commands and propagating itself to other vulnerable devices.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/louiseichenbaum\/\" target=\"_blank\" rel=\"noopener\">Louis Eichenbaum<\/a>, federal chief technology officer at ColorTokens, said the campaign calls for better mitigation strategies. \u201cWhen a vulnerable device cannot be remediated immediately, defenders should be able to place compensating controls around it, restricting its Internet exposure, limiting what it can communicate with and closely monitoring its behavior until the vulnerability can be resolved,\u201d he said.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Hiding where defenders may not look<\/h2>\n<p class=\"wp-block-paragraph\">ClingSTUN was found targeting a wide range of products, including Hytec routers, EnGenius IoT services, D-Link devices, TP-Link Archer AX21 routers, AVTECH cameras and other equipment. The researchers said the malware currently has multiple known entry points and continues to evolve, with additional vulnerabilities being incorporated into the attack chain.<\/p>\n<p>\u201cUpdates take time to test and deploy, some operational and IoT devices cannot be taken offline easily, and many legacy products are no longer supported by their manufacturers,\u201d Eichenbaum noted. \u201cAttackers understand this reality and continue targeting known vulnerabilities because those weaknesses remain effective.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Once installed, ClingSTUN takes steps to make removal and detection more difficult. It copies itself to hidden locations, adds entries to \/etc\/inittab, \/etc\/init.d\/rcs, and \/etc\/rc.d\/rc.boot to launch at startup, kills competing processes, and disables the watchdog timer.<\/p>\n<p class=\"wp-block-paragraph\">It can also hide its process information by making its \u201c\/proc\u201d entry resemble the system\u2019s init process, the researchers said in a <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/clingstun-linux-backdoor-abuses-public-stun-infrastructure\">blog post<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The malware also supports multiple Linux architectures, including ARM, Intel 80386, MIPS, PowerPC and x86-64, allowing the same operation to target a broad range of embedded hardware.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>The malware uses legitimate STUN traffic<strong><\/strong><\/h2>\n<p class=\"wp-block-paragraph\">STUN is normally used to help applications discover their public-facing IP address and port and establish connectivity through Network Address Translation (NAT). ClingSTUN abuses this infrastructure rather than using exclusive attacker-controlled servers.<\/p>\n<p class=\"wp-block-paragraph\">Fortinet observed the malware sending standard STUN binding requests to public endpoints, then periodically sending identifying information and mapped-port data to those services. The network security company said the malware contains exploits for seven vulnerabilities that can be used to spread to additional devices.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIts use of legitimate public STUN services shows why checking a destination\u2019s reputation is not enough to judge whether traffic is safe,\u201d Soroko said. \u201cSecurity teams should investigate why a device is making those connections, rather than assume the service it contacts is malicious or compromised.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The device\u2019s behavior matters more than whether the destination appears on a blocklist, he noted.<\/p>\n<p class=\"wp-block-paragraph\">For defenders, Fortinet recommends maintaining an accurate inventory of internet-facing devices, tracking firmware and support status, applying available security updates, and isolating or replacing equipment that can no longer be patched.<\/p>\n<p class=\"wp-block-paragraph\">Security teams should also look for suspicious processes, unexpected <a href=\"https:\/\/www.csoonline.com\/article\/2071104\/udp-based-network-communications-face-critical-denial-of-service-attacks.html\">UDP<\/a> connections, and recurring STUN traffic, alongside the indicators of compromise provided by Fortinet.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A new Linux backdoor is turning vulnerable internet-facing devices into remotely controlled proxy nodes, while using the public Session Traversal Utilities for NAT (STUN) infrastructure to blend into normal VoIP and WebRTC traffic. Fortinet\u2019s FortiGuard Labs said it has been tracking the malware, dubbed ClingSTUN, across multiple attacks exploiting known vulnerabilities in routers, IoT devices, [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9919,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9918","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9918"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9918"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9918\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9919"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}