ClingSTUN malware exploits IoT vulnerabilities as stealth proxy network
A new Linux malware, called ClingSTUN or Cling, is turning unpatched and vulnerable internet-facing IoT devices into remote-controlled proxy nodes by abusing legitimate STUN servers. Security researchers have tracked the campaign exploiting over 24 different known device vulnerabilities, including flaws in Realtek SDK, D-Link, and Ivanti products. The malware uses techniques that mask its traffic as regular VoIP or WebRTC activity, making detection and remediation significantly harder for defenders.
- Exploits more than 24 known IoT vulnerabilities
- Uses STUN protocol to disguise malicious traffic
- Acts as a proxy for remote command execution
- Targets routers and DVRs from multiple vendors
- Security experts debate network segmentation effectiveness
Sources covering this
How it unfolded
- The Hacker News Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
- SecurityWeek Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
- Infosecurity Magazine ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes
- Dark Reading ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
More in Cybersecurity
CrowdStrike launches Falcon Data Security for SaaS in Microsoft 365
CrowdStrike has announced general availability of Falcon Data Security for SaaS, a new product that secures sensitive data within…
Meta fixed major security flaw in Muse AI before launch
Meta engineers identified and urgently fixed several security vulnerabilities in its Muse AI agent just weeks before launch, according…
Dell System Update flaw exposes servers to remote code execution
Dell has alerted customers to a critical security flaw in its System Update tool for PowerEdge servers, which could allow remote…
Denmark population database breach exposes 8.8 million records
Denmark’s Central Population Register, which tracks personal details for all residents and citizens, suffered a data breach affecting…