Security researchers have discovered a new Linux backdoor called ClingSTUN that can turn infected systems into proxies and spread itself to other devices.
According to Fortinet’s FortiGuard Labs, the malware targets about two dozen known vulnerabilities in devices from vendors including D-Link, TP-Link, Tenda, Realtek, Ivanti and others. It also contains exploits for seven vulnerabilities that help it spread from one infected system to another.
ClingSTUN can remain active after a system restarts by copying itself into hidden files and adding commands to system startup scripts. It supports several processor types, including x86-64, ARM, MIPS and PowerPC.
The malware also uses the STUN protocol, a legitimate technology normally used to discover public IP addresses and network ports.
ClingSTUN leverages public STUN servers to help maintain connections through NAT and disguise the malicious activity.
Researchers found that the malware can kill rival malware, run remote commands and trigger its self-spreading functions. FortiGuard Labs warned that defenders should look for unusual UDP traffic, suspicious processes and repeated connection activity when investigating possible infections.