Fortinet Flags ClingSTUN Linux Backdoor Abusing STUN to Bypass NAT
Medium · Security Affairs ·
Key points
- ClingSTUN is a Linux malware family that abuses public STUN infrastructure.
- It routes command traffic around NAT boundaries, complicating detection and blocking.
- Targets are unpatched IoT devices, where it can deploy a backdoor.
- Fortinet is the vendor linked to the findings; no CVE has been assigned.
- Severity is medium, but exposure grows with unmanaged IoT.
Fortinet is the vendor named in connection with a Linux malware family called ClingSTUN. The malware is described as a backdoor that takes advantage of public STUN services, which are normally used to help real-time communications traverse network address translation. By leaning on these public servers, ClingSTUN can send traffic around NAT boundaries and make its command channel blend into ordinary outbound activity.
The main victims are IoT devices that have not received security updates. After gaining access, the malware can deploy a backdoor and maintain a foothold on systems that are often overlooked by endpoint protection and patch management. Many IoT appliances run Linux, lack agents, and remain exposed for years, making them attractive for this kind of intrusion.
The NAT bypass is significant because organizations frequently depend on NAT and firewalls to hide internal addresses and limit inbound reachability. If malicious code can use public STUN to relay or punch through connections, it may sustain command-and-control without obvious port forwarding. That undermines the assumption that internal IoT devices are unreachable from the internet.
No CVE identifiers are tied to this activity, so patching a single known flaw will not address it. Defenders need to focus on behavior, network flows, and device hygiene instead. Fortinet's role in the available information points to vendor visibility, but ClingSTUN itself is a Linux malware family rather than a flaw in a specific Fortinet product.
What to watch: unexpected STUN sessions from IoT segments, unexplained persistence on Linux-based appliances, and new binaries on devices that should not change. Because the severity is medium, prioritize internet-facing and unsupported IoT, segment those networks, and monitor for STUN abuse. If ClingSTUN evolves, it could expand to other Linux systems.
What to do now
- Inventory all IoT and Linux-based devices, especially internet-facing or unsupported units, and isolate them on restricted VLANs.
- Block or tightly control outbound STUN traffic from IoT segments unless a documented business need exists.
- Monitor network flows for unexpected STUN sessions, long-lived connections, or traffic that bypasses NAT policy.
- Hunt for unauthorized binaries, persistence mechanisms, and unusual processes on Linux appliances and IoT gateways.
- Apply vendor firmware updates and replace end-of-life IoT devices that cannot be patched.
- Restrict management interfaces and enforce least-privilege access to IoT networks.
- Review firewall and NAT logs for anomalous outbound connections from IoT devices and escalate medium-severity findings.
Original source
Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.