<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Stun - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/stun/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 18:44:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/stun/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>ClingSTUN Linux Backdoor Exploits Public STUN Infrastructure</title><link>https://feed.craftedsignal.io/briefs/2026-10-clingstun-backdoor/</link><pubDate>Mon, 05 Oct 2026 18:44:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-clingstun-backdoor/</guid><description>ClingSTUN is a Linux-based backdoor that leverages public Session Traversal Utilities for NAT (STUN) infrastructure to facilitate unauthorized proxy access and C2 communication.</description><content:encoded><![CDATA[<p>ClingSTUN is a Linux-based backdoor identified by FortiGuard Labs that abuses public STUN (Session Traversal Utilities for NAT) server infrastructure to establish C2 connectivity. By leveraging the STUN protocol, the malware facilitates persistent proxy relay capabilities on compromised Linux devices. This technique allows the backdoor to bypass standard NAT and firewall inspection, as the traffic mimics legitimate STUN requests used for NAT traversal. This approach enables attackers to maintain a covert proxy relay, potentially turning compromised devices into nodes for wider malicious activity or anonymous data exfiltration. The use of public infrastructure for C2 obfuscation complicates traditional network-based detection, requiring defenders to focus on the behavior of the binary and the specific communication patterns associated with STUN-based tunneling.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial exploitation of a vulnerable Linux-based service or device.</li>
<li>Deployment of the ClingSTUN binary onto the target filesystem.</li>
<li>Execution of the ClingSTUN process to establish persistence on the infected host.</li>
<li>Initialization of the STUN protocol client module within the malware.</li>
<li>Transmission of crafted STUN packets to public STUN servers to perform NAT traversal.</li>
<li>Establishment of an outbound C2 tunnel through the STUN-facilitated NAT hole.</li>
<li>Activation of proxy relay functionality, allowing remote attackers to tunnel traffic through the compromised host.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful deployment of ClingSTUN results in the creation of a persistent, covert proxy relay on the compromised Linux device. This allows attackers to route arbitrary malicious traffic through the victim network, effectively masking the true origin of their attacks and facilitating unauthorized access to internal resources. The impact includes data exfiltration, lateral movement, and the utilization of victim infrastructure as an anonymization layer for broader campaigns.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Monitor network logs for anomalous STUN traffic originating from servers or internal infrastructure that do not typically require NAT traversal.</li>
<li>Implement egress filtering to restrict outbound communication to known, authorized STUN servers.</li>
<li>Deploy endpoint monitoring to identify unauthorized binaries executing from common persistence locations on Linux systems.</li>
<li>Conduct memory forensics on high-value Linux targets to identify dormant or beaconing proxy processes.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>linux</category><category>backdoor</category><category>c2</category><category>proxy</category><category>stun</category></item></channel></rss>