New Linux malware turns vulnerable IoT devices into proxy nodes
Fortinet says ClingSTUN Linux malware exploits known IoT flaws to turn devices into STUN-backed proxy nodes.
Fortinet's FortiGuard Labs is tracking ClingSTUN, a Linux backdoor that compromises internet-facing routers, cameras, DVRs, and other IoT devices and turns them into remotely controlled proxy nodes. Attackers have exploited known command-injection, code-injection, and buffer-overflow flaws in products from Hytec, EnGenius, D-Link, TP-Link, and AVTECH, and the malware contains exploits for seven vulnerabilities. After installation it persists through init and rc scripts, hides its process, disables the watchdog, runs commands, and spreads to other devices across ARM, MIPS, PowerPC, x86, and x86-64. It blends command-and-control into legitimate public STUN traffic used by VoIP and WebRTC.