ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.
Read more →
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.
FortiGuard Labs identified a back door for Linux that leverages known vulnerabilities on IoT devices and uses public STUN servers to keep them accessible as proxy nodes. The campaign incorporated new bugs over three periods and opened a discussion among specialists on whether to prioritize network segmentation or firmware remediation.