Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
FortiGuard Labs says ClingSTUN Linux backdoor abuses STUN and exploits dozens of device flaws to spread.
FortiGuard Labs described ClingSTUN, a Linux back-connect proxy backdoor that abuses public STUN servers to learn external IP addresses and port mappings. Operators were seen indiscriminately exploiting vulnerabilities in Avtech, EnGenius, D-Link, TP-Link, Ivanti, Realtek, Tenda, and other device vendors, and the malware hardcodes exploits for seven further China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK flaws to spread. Downloaders retrieve payloads for AMD x86-64, ARM, Intel 80386, MIPS R3000, and PowerPC. It kills rival processes, disables a watchdog, copies itself to hidden executables, appends commands to three init scripts, and accepts packets that trigger remote code execution and propagation.