Malware Targets a Growing List of IoT Vulnerabilities Fortinet’s FortiGuard Labs researchers identified the malware, which they have dubbed "ClingSTUN," after tracking attacks targeting at least 24 known vulnerabilities in IoT devices.
Leveraging Legitimate STUN Servers ClingSTUN periodically sent that information back to the STUN servers.
In comments to Dark Reading, Li says ClingSTUN demonstrates how vulnerable Internet-facing Linux and IoT devices can become infrastructure for malicious proxy operations.
Therefore, indiscriminately blocking public STUN servers to address the ClingSTUN threat could disrupt legitimate services.
John Gallagher, vice president at Viakoo, says ClingSTUN is a textbook example of how operational technology (OT) and IoT devices remain the enterprise's vulnerable soft underbelly.