ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
Summary
A new Linux backdoor, dubbed ClingSTUN, has been identified that exploits 24 known vulnerabilities in IoT devices. Once compromised, these devices are turned into proxy nodes, with their communications masked by legitimate public STUN servers.
IFF Assessment
FOE
This finding is bad news for defenders as it demonstrates a new method for compromising IoT devices and creating botnets that are harder to detect.
Defender Context
Defenders should be aware of this new backdoor's ability to leverage multiple known vulnerabilities in IoT devices. The use of STUN servers for obfuscation makes detection and mitigation more challenging, requiring enhanced network monitoring and timely patching of known IoT device flaws.