ClingSTUN Linux Backdoor Exploits 24 IoT Vulnerabilities to Create Proxy Nodes
Threat actors leverage legitimate public STUN servers to obscure C2 traffic from compromised devices

Key Takeaways
- A Linux backdoor named ClingSTUN exploits 24 known vulnerabilities in IoT devices.
- Compromised devices are repurposed as proxy nodes to route traffic.
- Legitimate public STUN servers are used to obscure command-and-control communications.
- The report lacks independent verification of CVE assignments and victim counts.
Related Security News

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet with STUN-Based C2
Nozomi Networks researchers report that threat actors have been attempting to exploit a critical vulnerability in the Realtek Jungle SDK. The exploitation delivers Cling botnet malware, which is notable for repurposing ordinary STUN (Session Traversal Utilities for NAT) behavior into a practical command-and-control channel. The vulnerability has since been patched. Users of the Realtek Jungle SDK are advised to update to the latest version to mitigate exploitation risk.



