LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
malware

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Fortinet's FortiGuard Labs has detailed a new Linux backdoor, dubbed ClingSTUN, which leverages legitimate public Session Traversal Utilities for NAT (STUN) infrastructure to mask its command and control (C2) communications. The malware primarily targets unpatched Internet of Things (IoT) devices, functioning as a back-connect proxy that turns compromised systems into remotely controlled nodes.

ZeroDay News ·

Source: Security Affairs

Fortinet's FortiGuard Labs has detailed a new Linux backdoor, dubbed ClingSTUN, which leverages legitimate public Session Traversal Utilities for NAT (STUN) infrastructure to mask its command and control (C2) communications. The malware primarily targets unpatched Internet of Things (IoT) devices, functioning as a back-connect proxy that turns compromised systems into remotely controlled nodes.

ClingSTUN's distinctive approach involves sending standard STUN binding requests to public STUN servers. This allows the malware to discover the external IP addresses and ports of infected devices, maintain NAT bindings, and improve connectivity for its operators. This traffic blends seamlessly with legitimate VoIP and WebRTC communications, making it difficult for network defenders to distinguish malicious activity from normal application usage.

The campaign initially exploited a known command injection vulnerability in Hytec Inter routers. Over time, the attackers expanded their targeting to include devices from a dozen additional vendors, such as D-Link, TP-Link, Realtek, and Linksys, along with various DVR and IoT cloud platforms. Many of these devices are susceptible due to infrequent updates and limited monitoring.

Upon successful exploitation, a small downloader script installs the appropriate ClingSTUN variant for the device's architecture, supporting ARM, MIPS, PowerPC, and Intel. Later versions of the malware also include a mechanism to scan for and eliminate competing malware by checking mounted filesystems and terminating suspicious processes running from temporary directories.

ClingSTUN establishes persistence by copying itself to two separate locations and appending itself to three different boot scripts, ensuring survival across reboots. It also employs a process integrity check, comparing running processes against their claimed command lines and terminating any discrepancies, a tactic that further eliminates rival malware.

Two notable features of ClingSTUN demonstrate sophisticated design. First, it disables the device's watchdog timer, preventing automatic reboots that could disrupt the infection. Second, when running with root privileges, it manipulates its process metadata to impersonate PID 1, the initial process started by the kernel. This makes the malware appear as the init system in basic process listings. After achieving persistence, ClingSTUN clears its original command-line arguments, making its command line appear empty in tools like `ps`. If running as root, it copies selected process information files from `/proc/1/` to `/tmp` and then bind-mounts `/tmp` over its own `/proc/` directory, effectively hiding its true process information behind that of PID 1.

For command delivery, ClingSTUN establishes a UDP socket, binds to a random local port, and sends 20-byte STUN binding requests to public endpoints. Initial versions targeted 24 endpoints, requiring at least half to succeed. Later iterations reduced this to 13 endpoints, demanding successful connections to all of them, indicating an effort to improve reliability. A single control datagram can trigger ClingSTUN to open an outbound TCP connection to an operator-specified address, download a command, and execute it, thereby offloading heavy data transfer from the STUN channel.

The malware also incorporates hardcoded exploits for seven additional vulnerabilities, enabling it to spread further by turning each infected device into a scanner for new targets. Fortinet emphasizes that the public STUN servers themselves are not compromised or malicious; they are simply being used as intended by the attackers.

Fortinet's report underscores the critical importance of robust cyber hygiene, including maintaining an inventory of internet-facing devices, tracking firmware and support status, and promptly applying security updates, especially for vulnerabilities known to be actively exploited.

malwarepatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-86360critical

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell has issued an urgent advisory to customers, recommending they patch a critical vulnerability in its System Update (DSU) tool that could allow attackers to gain root access on affected PowerEdge servers. The flaw, identified as CVE-2026-86360, carries a CVSS score of 9.6, indicating its severe potential impact.

CVE-2026-21589critical

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical vulnerability has been reported in eight Atlassian Data Center products, enabling unauthenticated attackers to read known files within the web application root directory. The flaw, identified as CVE-2026-21589, was disclosed by Atlassian on October 5th and carries a CVSS rating of 9.3 out of 10, indicating its severe impact and ease of exploitation.

breach

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has reportedly removed an Accenture contractor following an alleged security failure that contributed to a data breach attributed to the ShinyHunters threat group. This incident is said to have resulted in the theft of personal details belonging to thousands of FBI employees. The reported cause of the breach was a patch failure.

ai

U.S. Bank CISO says the security role keeps growing and no one can own all of it

The role of a Chief Information Security Officer (CISO) has expanded significantly to encompass areas such as fraud, resilience, third-party risk, and AI governance, according to Ann Barron-DiCamillo, EVP and CISO at U.S. Bank. She notes that while this consolidation can make security leaders more effective by addressing interconnected risks, no single individual can realistically own every…

nation-state

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Denmark's digitalization ministry has reported that unauthorized parties accessed the Central Person Register (CPR), the national population register, compromising data for approximately 8.8 million individuals. The accessed information includes names, addresses, and personal identification numbers. This incident, reported on October 5, affects both living and deceased persons registered in…

CVE-2026-88779high

Citrix NetScaler Hit by Third Actively Exploited Zero-Day

Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two…