ConciseSignal
Following

ClingSTUN malware exploits IoT vulnerabilities as stealth proxy network

A new Linux malware, called ClingSTUN or Cling, is turning unpatched and vulnerable internet-facing IoT devices into remote-controlled proxy nodes by abusing legitimate STUN servers. Security researchers have tracked the campaign exploiting over 24 different known device vulnerabilities, including flaws in Realtek SDK, D-Link, and Ivanti products. The malware uses techniques that mask its traffic as regular VoIP or WebRTC activity, making detection and remediation significantly harder for defenders.

Why it mattersClingSTUN demonstrates how attackers can exploit unpatched IoT devices and repurpose standard internet protocols for stealthy command-and-control. The prevalence of vulnerable devices and the use of benign-appearing traffic raise new challenges for both detection and effective security controls.

Sources covering this

The Hacker NewsRealtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C211:46 AM →SecurityWeekHeadline onlyLinux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws1:00 PM →Infosecurity MagazineClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes2:30 PM →Dark ReadingHeadline onlyClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes9:25 PM →

How it unfolded

  • The Hacker News Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
  • SecurityWeek Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
  • Infosecurity Magazine ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes
  • Dark Reading ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity