Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    October 5, 2026

    Google DeepMind Gives AI-Designed Proteins a Watermark

    October 5, 2026

    I tested Noble’s elite triple-driver wireless headphones and they offer some of the most hypnotic, spacious sound I’ve ever heard — if you can afford them

    October 5, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
    Cybersecurity

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    The Tech GuyBy The Tech GuyOctober 5, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    A recently discovered Linux backdoor turns infected systems into proxies that use the Session Traversal Utilities for NAT (STUN) protocol and contains exploits for self-propagation, FortiGuard Labs reports.

    Advertisement

    Dubbed ClingSTUN and functioning as a back-connect proxy backdoor, the malware targets two dozen vulnerabilities for initial access and sets up persistence to ensure malware execution during the boot sequence.

    The malware’s operators were seen indiscriminately exploiting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link flaws, and appear to be expanding their portfolio with other exploits as well.

    Additionally, the backdoor includes a self-propagation mechanism containing hardcoded exploits for seven China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK vulnerabilities.

    The ClingSTUN backdoor relies on downloaders to fetch malware payloads for different architectures, including AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC.

    Across three variants of the botnet, FortiGuard Labs observed the same behavior related to killing competitors’ processes, terminating a watchdog timer, setting up the persistence mechanism, and executing remote commands.

    Advertisement. Scroll to continue reading.

    For persistence, ClingSTUN copies itself to two hidden files with executable permissions, then appends startup commands to three system initialization scripts.

    Additionally, it establishes a UDP socket, binds to a random local port, and sends standard STUN binding requests to set up endpoint connections.

    “After completing the STUN binding exchanges, ClingSTUN periodically sends its group identifier and mapped-port list to the same STUN endpoints. No separate coordination-server registration was identified in this path,” FortiGuard Labs says.

    The malware was also seen listening to specific packets that allow its operators to perform remote code execution and trigger the self-propagation mechanism.

    “A notable feature is its abuse of legitimate public STUN servers to discover external IP addresses and port mappings, thereby helping maintain NAT connectivity. These third-party services should not be automatically classified as attacker-controlled infrastructure. Instead, defenders should assess STUN activity alongside suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic,” FortiGuard Labs notes.

    Related: macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    Related: AI Agents Aimed SQL Injection at US and Canadian Government Sites

    Related: Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

    Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

    October 5, 2026

    Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 

    October 5, 2026

    Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

    October 5, 2026

    Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

    October 4, 2026

    Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    October 4, 2026

    AI Agents Aimed SQL Injection at US and Canadian Government Sites

    October 4, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026392 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    October 5, 2026

    Google DeepMind Gives AI-Designed Proteins a Watermark

    October 5, 2026

    I tested Noble’s elite triple-driver wireless headphones and they offer some of the most hypnotic, spacious sound I’ve ever heard — if you can afford them

    October 5, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.