A Linux backdoor called ClingSTUN leverages 24 known vulnerabilities to compromise Internet of Things devices and convert them into proxy nodes for malicious traffic. The malware exploits publicly disclosed flaws in IoT device software to establish initial access, according to reporting from Dark Reading.

Once installed, ClingSTUN uses legitimate STUN (Session Traversal Utilities for NAT) servers to hide its command-and-control communications. STUN is a standard protocol used for network address translation traversal, making the backdoor's traffic blend with normal network activity. This obfuscation technique allows the malware to evade detection by security tools monitoring for suspicious outbound connections.

The compromised IoT devices function as proxy nodes in a larger infrastructure, routing traffic through the infected systems. This setup enables attackers to conduct various malicious activities while obscuring the true origin of their operations. The use of legitimate infrastructure for command-and-control purposes complicates defensive efforts.

The backdoor targets Linux-based IoT systems, a category encompassing millions of devices deployed across consumer and enterprise networks. By exploiting known vulnerabilities rather than zero-day flaws, ClingSTUN benefits from the prevalence of unpatched systems in IoT environments. Organizations often struggle to maintain consistent patching cycles for distributed IoT devices, leaving them exposed to exploitation of known issues.

The campaign demonstrates how attackers combine multiple attack vectors to maximize reach and effectiveness. The reliance on 24 distinct vulnerabilities suggests ClingSTUN operators cast a wide net to compromise diverse IoT device types and configurations. This approach increases the likelihood of successfully establishing footholds across heterogeneous device ecosystems.

The use of proxy nodes built from IoT devices creates challenges for network defenders. Traffic originating from compromised IoT systems appears legitimate and originates from diverse network locations, making it harder to identify coordinated