A new Linux backdoor is turning vulnerable internet-facing devices into remotely controlled proxy nodes, while using the public Session Traversal Utilities for NAT (STUN) infrastructure to blend into normal VoIP and WebRTC traffic.

Fortinet’s FortiGuard Labs said it has been tracking the malware, dubbed ClingSTUN, across multiple attacks exploiting known vulnerabilities in routers, IoT devices, DVRs and other network-connected hardware.

Fortinet described it as a “back-connect proxy backdoor” capable of maintaining persistence, executing remote commands and propagating itself to other vulnerable devices.

The malware uses legitimate STUN traffic STUN is normally used to help applications discover their public-facing IP address and port and establish connectivity through Network Address Translation (NAT).

The network security company said the malware contains exploits for seven vulnerabilities that can be used to spread to additional devices.