Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

Summary

A new Linux backdoor, dubbed ClingSTUN, has been discovered that utilizes the STUN protocol to act as a back-connect proxy. This backdoor establishes persistence and includes exploits designed for self-propagation, leveraging dozens of previously identified vulnerabilities.

IFF Assessment

FOE

The discovery of a new, self-propagating Linux backdoor that abuses STUN and exploits numerous vulnerabilities poses a significant threat to system security.

Defender Context

This discovery highlights the ongoing threat of sophisticated backdoors targeting Linux systems. Defenders should be vigilant for unusual STUN protocol activity and ensure systems are patched against known vulnerabilities that could be exploited for propagation.

Read Full Story →