Linux Backdoor ClingSTUN Abuses STUN Protocol, Exploits Dozens of Flaws for Self-Propagation
A new Linux backdoor, dubbed ClingSTUN, operates as a sophisticated back-connect proxy, establishing persistence and leveraging numerous vulnerabilities for self-propagation while using the STUN protocol for command and control.

A newly identified Linux backdoor, named ClingSTUN, has emerged, operating as a persistent back-connect proxy on compromised systems. This sophisticated malware is designed not only to maintain its foothold but also to actively seek out and exploit numerous vulnerabilities, enabling it to propagate itself across networks without direct human intervention.
The primary function of ClingSTUN is to establish a covert communication channel back to its operators. Unlike typical backdoors that might rely on simple reverse shells, ClingSTUN acts as a proxy, allowing attackers to tunnel traffic through the compromised machine. This can be used for a variety of malicious purposes, including launching further attacks, exfiltrating data, or maintaining persistent access to sensitive network segments.
A key feature of ClingSTUN is its self-propagation capability. The backdoor is reportedly equipped with exploits for dozens of vulnerabilities. This allows it to scan for and compromise other vulnerable systems within its reach, effectively expanding its botnet without requiring manual effort from the threat actors. The specific vulnerabilities targeted are not yet fully detailed, but the sheer number suggests a broad attack surface is being leveraged.
Furthermore, ClingSTUN employs an unusual method for its command and control (C2) communications: it abuses the Session Traversal Utilities for NAT (STUN) protocol. STUN is a standard network protocol used to discover the public IP address and port that a client is using to connect to a network, particularly useful for peer-to-peer applications behind NAT firewalls. By masquerading its C2 traffic as legitimate STUN requests or responses, ClingSTUN aims to evade detection by network security devices that might otherwise flag or block suspicious C2 channels.
This technique of using common, legitimate protocols for C2 is a growing trend among sophisticated threat actors seeking to blend in with normal network traffic. The use of STUN, in particular, is less common than other protocols like HTTP or DNS, potentially making it harder for security analysts to identify and block.
The implications of ClingSTUN are significant for Linux environments, which are widely used in servers, cloud infrastructure, and embedded devices. The backdoor's ability to self-propagate and its stealthy C2 mechanism pose a considerable threat to organizations running these systems. The reliance on exploiting multiple vulnerabilities means that even systems that are not directly exposed to the internet could be at risk if they are connected to an already compromised network.
Security researchers are actively analyzing ClingSTUN to identify the full scope of its capabilities, the specific vulnerabilities it exploits, and the extent of its deployment. Organizations are advised to ensure their Linux systems are up-to-date with security patches, monitor network traffic for unusual STUN protocol usage, and implement robust endpoint detection and response (EDR) solutions to detect and mitigate the presence of such advanced backdoors.
The latest reporting on the ClingSTUN backdoor details its evolution across three distinct campaign periods, each utilizing different download servers and expanding its arsenal of exploited vulnerabilities. The third period notably incorporated command injection flaws across a wider range of devices from vendors including Linear, Realtek, TP-Link, AVTECH, and D-Link, alongside previously known Ivanti Connect Secure flaws and newer vulnerabilities like CVE-2026-36356 and CVE-2025-67038.