โ† Back to Feed

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

October 5, 2026 ยท Fortinet Threat Research ยท Severity: HIGH

This article from FortiGuard Labs analyzes ClingSTUN, a Linux backdoor that exploits vulnerable devices and misuses public STUN servers to support a proxy backdoor. The malware abuses STUN infrastructure to hide its communications, making it harder to detect. ๐Ÿ“Œ **Analyst Note:** The abuse of legitimate protocols like STUN for malicious purposes is a growing trend that threatens the security of Internet infrastructure. Security teams should monitor for unusual STUN traffic patterns as an indicator of compromise.

FortiGuard Labs examines how ClingSTUN exploits vulnerable devices and abuses public STUN servers to support a Linux proxy backdoor.

      

Key Takeaways

  • ClingSTUN is a Linux backdoor that exploits vulnerable devices and abuses public STUN servers to establish a proxy connection, allowing attackers to maintain persistent access.
  • The malware uses STUN infrastructure, which is typically used for NAT traversal, to hide its command-and-control communications, making detection more difficult for security tools.
  • FortiGuard Labs discovered that ClingSTUN targets Linux systems and leverages publicly available STUN servers, demonstrating a novel technique for evading network-based defenses.
โ˜• Buy a Coffee