> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> New Linux malware turns vulnerable IoT devices into proxy nodes

[SOURCE] CSO Online [DATE: 06/10/2026 11:49] [LANGUAGE: EN]
New Linux malware turns vulnerable IoT devices into proxy nodes
A new Linux backdoor is turning vulnerable internet-facing devices into remotely controlled proxy nodes, while using the public Session Traversal Utilities for NAT (STUN) infrastructure to blend into normal VoIP and WebRTC traffic. Fortinet’s FortiGuard Labs said it has been tracking the malware, dubbed ClingSTUN, across multiple attacks exploiting known vulnerabilities in routers, IoT devices, DVRs and other network-connected hardware. The malware was seen exploiting flaws including command injection, code injection, and buffer overflows to gain an initial foothold, with Fortinet observing attackers switch between different vulnerabilities and download sources as the campaign evolved. “A device does not need to hold sensitive data to be useful to an attacker,” said Jason Soroko, senior fellow at Sectigo. “ClingSTUN lets attackers relay traffic through compromised devices and run commands on them.” That makes the compromised device useful even when it is not itself a valuable target. Fortinet described it as a “back-connect proxy backdoor” capable of maintaining persistence, executing remote commands and propagating itself to other vulnerable devices. Louis Eichenbaum, federal chief technology officer at ColorTokens, said the campaign calls for better mitigation strategies. “When a vulnerable device cannot be remediated immediately, defenders should be able to place compensating controls around it, restricting its Internet exposure, limiting what it can communicate with and closely monitoring its behavior until the vulnerability can be resolved,” he said. Hiding where defenders may not look ClingSTUN was found targeting a wide range of products, including Hytec routers, EnGenius IoT services, D-Link devices, TP-Link Archer AX21 routers, AVTECH cameras and other equipment. The researchers said the malware currently has multiple known entry points and continues to evolve, with additional vulnerabilities being incorporated into the attack chain.“Updates take time to test and deploy, some operational and IoT devices cannot be taken offline easily, and many legacy products are no longer supported by their manufacturers,” Eichenbaum noted. “Attackers understand this reality and continue targeting known vulnerabilities because those weaknesses remain effective.” Once installed, ClingSTUN takes steps to make removal and detection more difficult. It copies itself to hidden locations, adds entries to /etc/inittab, /etc/init.d/rcs, and /etc/rc.d/rc.boot to launch at startup, kills competing processes, and disables the watchdog timer. It can also hide its process information by making its “/proc” entry resemble the system’s init process, the researchers said in a blog post. The malware also supports multiple Linux architectures, including ARM, Intel 80386, MIPS, PowerPC and x86-64, allowing the same operation to target a broad range of embedded hardware. The malware uses legitimate STUN traffic STUN is normally used to help applications discover their public-facing IP address and port and establish connectivity through Network Address Translation (NAT). ClingSTUN abuses this infrastructure rather than using exclusive attacker-controlled servers. Fortinet observed the malware sending standard STUN binding requests to public endpoints, then periodically sending identifying information and mapped-port data to those services. The network security company said the malware contains exploits for seven vulnerabilities that can be used to spread to additional devices. “Its use of legitimate public STUN services shows why checking a destination’s reputation is not enough to judge whether traffic is safe,” Soroko said. “Security teams should investigate why a device is making those connections, rather than assume the service it contacts is malicious or compromised.” The device’s behavior matters more than whether the destination appears on a blocklist, he noted. For defenders, Fortinet recommends maintaining an accurate inventory of internet-facing devices, tracking firmware and support status, applying available security updates, and isolating or replacing equipment that can no longer be patched. Security teams should also look for suspicious processes, unexpected UDP connections, and recurring STUN traffic, alongside the indicators of compromise provided by Fortinet.
[messages.read_original_source] →