Fortinet details ClingSTUN, a Linux backdoor exploiting unpatched IoT devices and abusing public STUN servers to route traffic past NAT.
FortiGuard Labs researchers spotted a Linux malware family they call ClingSTUN, and the name gives away its trick immediately.
It abuses public STUN (Session Traversal Utilities for NAT) infrastructure to discover externally mapped IP addresses and ports, maintain NAT bindings, and improve connectivity between compromised hosts and remote operators.”
“Because many of the STUN servers it contacts are legitimate public services, the resulting traffic easily blends with normal VoIP and WebRTC communications.”
The malware sends standard requests to public STUN servers to find out its external IP address and port.