{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/stun/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["linux","backdoor","c2","proxy","stun"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eClingSTUN is a Linux-based backdoor identified by FortiGuard Labs that abuses public STUN (Session Traversal Utilities for NAT) server infrastructure to establish C2 connectivity. By leveraging the STUN protocol, the malware facilitates persistent proxy relay capabilities on compromised Linux devices. This technique allows the backdoor to bypass standard NAT and firewall inspection, as the traffic mimics legitimate STUN requests used for NAT traversal. This approach enables attackers to maintain a covert proxy relay, potentially turning compromised devices into nodes for wider malicious activity or anonymous data exfiltration. The use of public infrastructure for C2 obfuscation complicates traditional network-based detection, requiring defenders to focus on the behavior of the binary and the specific communication patterns associated with STUN-based tunneling.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial exploitation of a vulnerable Linux-based service or device.\u003c/li\u003e\n\u003cli\u003eDeployment of the ClingSTUN binary onto the target filesystem.\u003c/li\u003e\n\u003cli\u003eExecution of the ClingSTUN process to establish persistence on the infected host.\u003c/li\u003e\n\u003cli\u003eInitialization of the STUN protocol client module within the malware.\u003c/li\u003e\n\u003cli\u003eTransmission of crafted STUN packets to public STUN servers to perform NAT traversal.\u003c/li\u003e\n\u003cli\u003eEstablishment of an outbound C2 tunnel through the STUN-facilitated NAT hole.\u003c/li\u003e\n\u003cli\u003eActivation of proxy relay functionality, allowing remote attackers to tunnel traffic through the compromised host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deployment of ClingSTUN results in the creation of a persistent, covert proxy relay on the compromised Linux device. This allows attackers to route arbitrary malicious traffic through the victim network, effectively masking the true origin of their attacks and facilitating unauthorized access to internal resources. The impact includes data exfiltration, lateral movement, and the utilization of victim infrastructure as an anonymization layer for broader campaigns.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eMonitor network logs for anomalous STUN traffic originating from servers or internal infrastructure that do not typically require NAT traversal.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering to restrict outbound communication to known, authorized STUN servers.\u003c/li\u003e\n\u003cli\u003eDeploy endpoint monitoring to identify unauthorized binaries executing from common persistence locations on Linux systems.\u003c/li\u003e\n\u003cli\u003eConduct memory forensics on high-value Linux targets to identify dormant or beaconing proxy processes.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-05T18:44:35Z","date_published":"2026-10-05T18:44:35Z","id":"https://feed.craftedsignal.io/briefs/2026-10-clingstun-backdoor/","summary":"ClingSTUN is a Linux-based backdoor that leverages public Session Traversal Utilities for NAT (STUN) infrastructure to facilitate unauthorized proxy access and C2 communication.","title":"ClingSTUN Linux Backdoor Exploits Public STUN Infrastructure","url":"https://feed.craftedsignal.io/briefs/2026-10-clingstun-backdoor/"}],"language":"en","title":"CraftedSignal Threat Feed - Stun","version":"https://jsonfeed.org/version/1.1"}