ClingSTUN hides IoT backdoor communications using public STUN servers

First reported by Cyber Security News at · Updated · 4 sources

The Linux malware compromises vulnerable internet-connected devices and turns them into proxy nodes, using legitimate STUN infrastructure to obscure its communications. Dark Reading reports that it exploits 24 known flaws. According to Cyber Security News, attacks begin against devices running vulnerable Realtek software, and control traffic masquerades as replies from Google's public STUN service.

  • SecurityWeek reports that ClingSTUN establishes persistence and includes exploits for self-propagation.
  • FortiGuard Labs identified the malware family, according to Security Affairs.

Covered by 4 publishers within 23 hours of the first report.

Reporting4

Cyber Security News Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices · Tushar Subhra Dutta
SecurityWeek Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws · Ionut Arghire
Dark Reading ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes · Jai Vijayan
Security Affairs ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure · Pierluigi Paganini

Related

Topics Google