ClingSTUN Malware Hijacks Unpatched Routers and Cameras to Run Hidden Proxy Networks
A Linux backdoor named ClingSTUN is turning vulnerable internet-connected devices into remotely controlled proxy nodes, according to research published on October 5 by FortiGuard Labs. The malware exploits known flaws that have not been patched. FortiGuard tracked the campaign across three periods, each using a different download server. It began with a single flaw in Hytec Inter routers, then widened to devices from EnGenius, D-Link, Linear, Realtek, TP-Link and AVTECH. FortiGuard's list now stands at 24 vulnerabilities, including Ivanti Connect Secure flaws.
Once inside, ClingSTUN contacts public STUN servers, which are legitimate services normally used for VoIP and WebRTC. This lets it discover its external address and keep a path open to the device, so the traffic looks like ordinary calling activity. FortiGuard said how the operator pushes commands through is unverified, and warned against treating the STUN services themselves as attacker-controlled. The malware also kills competing processes, copies itself into system locations, edits boot scripts to survive restarts, and disguises itself as a system process. It supports remote command execution and carries built-in exploits for seven more vulnerabilities to spread.
Louis Eichenbaum of ColorTokens said organisations cannot patch their way out of cyber risk, and argued for extra controls around devices that cannot be fixed immediately, including microsegmentation. John Gallagher of Viakoo disagreed on segmentation.