CyberSecurity SEE

ClingSTUN Malware Converts Unpatched IoT Devices into Proxy Nodes

ClingSTUN Malware Converts Unpatched IoT Devices into Proxy Nodes

Title: The Emergence of ClingSTUN: A New Cyber Threat Targeting IoT Devices

In recent cybersecurity developments, a Linux proxy backdoor, identified as ClingSTUN, has raised significant alarms as it exploits known, unpatched vulnerabilities in internet-facing Internet of Things (IoT) devices. The malware also takes advantage of legitimate public Session Traversal Utilities for NAT (STUN) servers to maintain connectivity for the compromised systems, effectively transforming them into remotely controlled proxy nodes.

FortiGuard Labs released a research article on October 5, highlighting the operation and characteristics of ClingSTUN. The report outlines a campaign tracked over three distinct phases, each demonstrating a different method of exploiting vulnerabilities through specific download servers.

Phased Attacks: A Case Study of Evolving Tactics

The initial phase of the attack lasted for two days and concentrated on exploiting a single vulnerability: CVE-2022-36553 in Hytec Inter routers. In this early stage, the attackers demonstrated the efficacy of focusing on widely used yet often neglectfully secured infrastructure.

In the subsequent phase, the threat actors diversified their approach, leveraging two additional vulnerabilities: CVE-2025-34035, which affects EnGenius’s IoT cloud service, and CVE-2024-23625 tied to D-Link’s Universal Plug and Play (UPnP) service. This shift illustrates how attackers adapt their strategies by targeting multiple vulnerabilities to expand their reach and impact.

During the third phase, the operators further enhanced their methods by broadening their entry points. FortiGuard’s findings now highlight a total of 24 vulnerabilities exploited by ClingSTUN, including significant weaknesses in Ivanti Connect Secure, identified by CVEs CVE-2023-46805 and CVE-2024-21887. Newer vulnerabilities, such as CVE-2026-36356 and CVE-2025-67038, have also been included, showcasing a concerning progression in the attack’s complexity and sophistication.

The Technical Mechanics of ClingSTUN

The functionality of ClingSTUN is particularly troubling as it acts as a back-connect proxy. It performs STUN binding requests to numerous public servers—24 during the second phase and 13 during the third phase. This technical maneuver allows ClingSTUN to ascertain its external address and port mappings while keeping Network Address Translation (NAT) bindings open. The malware periodically sends reports containing the group identifier and corresponding mapped ports back to the same servers.

A notable aspect of this malware is its ability to masquerade as normal VoIP and WebRTC traffic due to the legitimate nature of the servers it utilizes. FortiGuard has pointed out the unverified methods the operator employs to receive mappings and execute commands through NAT, issuing a warning against any assumptions that STUN services are entirely under attacker control.

The malware is also designed to eliminate competing processes and watchdog timers, effectively safeguarding its own operation. It replicates itself within system directories, alters boot scripts to ensure persistence, and obscures its presence by adopting process information from the system’s initialization process. Furthermore, it supports remote command execution and is equipped with hard-coded exploits targeting seven additional vulnerabilities across multiple platforms, including notable flaws within Realtek’s SDK and various DVR products.

Expert Opinions: Managing Cyber Risk in IoT

In reaction to the emergence of ClingSTUN, cybersecurity professionals are weighing their options for managing this growing threat. Louis Eichenbaum, the federal CTO at ColorTokens, emphasized the critical nature of the situation, asserting that “ClingSTUN is another reminder that organizations cannot patch their way out of cyber risk.” He advocates for compensating controls around unsupported or unpatchable devices, recommending the implementation of microsegmentation to restrict lateral movement.

Conversely, John Gallagher, the VP of IoT security firm Viakoo, voiced concern over the effectiveness of network segmentation. He argued that reliance on segmentation as a security measure is fundamentally flawed. Gallagher instead advocates for automated firmware remediation across diverse IoT devices as a necessary countermeasure, emphasizing that mere visibility into the network will not suffice.

FortiGuard Labs provides several recommendations aimed at curbing the impact of ClingSTUN. They emphasize the importance of monitoring STUN activity alongside suspicious processes and unexpected UDP connections. Furthermore, organizations are urged to conduct comprehensive inventories of their internet-facing devices, prioritize patching actively exploited vulnerabilities, and consider replacing or isolating devices that no longer receive security updates.

Conclusion

As the cyber landscape continues to evolve, the emergence of threats like ClingSTUN underscores the pressing need for vigilance, adaptability, and a multi-faceted approach to cybersecurity. Organizations must remain proactive in their security measures, understanding that static defenses are no longer sufficient in the face of rapidly shifting tactics employed by cybercriminals. The battle against such malware is not one that can be won solely through patching; it requires comprehensive strategies that encompass visibility, control, and risk management.

Source link

Exit mobile version