New Malware Leveraging STUN Servers Converts Vulnerable IoT Gadgets into Proxy Relays
Security researchers have identified a fresh strain of malware, dubbed ClingSTUN, that silently transforms unsecured Internet of Things (IoT) devices into proxy nodes. By exploiting well‑known firmware weaknesses, the code gains footholds on routers, cameras, and other connected hardware, then uses publicly available Session Traversal Utilities for NAT (STUN) servers to maintain outbound pathways for further malicious traffic.
The technique differs from traditional botnets that rely on direct command‑and‑control channels. Instead, ClingSTUN routes its traffic through the compromised devices themselves, masking the origin of attacks and making detection harder for network defenders. Public STUN servers, originally intended to aid real‑time communication apps in traversing NAT devices, are repurposed as relay points, allowing the malware to bypass firewalls without raising immediate suspicion.
Experts note that the vulnerabilities ClingSTUN targets have been documented for years, yet many manufacturers continue to ship devices without timely patches. The malware scans for default credentials, outdated firmware versions, and unsecured services, then installs a lightweight proxy daemon that can be activated on demand. Because the proxy traffic mimics legitimate STUN packets, intrusion‑detection systems often overlook the activity.
Infosecurity Magazine first reported the discovery, highlighting that the proxy network created by ClingSTUN could be employed for a range of illicit purposes, from credential harvesting to distributed denial‑of‑service (DDoS) attacks. The ability to route traffic through a dispersed set of IoT endpoints also raises concerns about privacy violations, as the compromised devices can intercept unencrypted data streams passing through them.
Mitigation efforts focus on hardening IoT deployments. Security professionals advise disabling unnecessary services, changing default passwords, and applying firmware updates as soon as they become available. Network operators are also urged to monitor outbound traffic for anomalous STUN‑related patterns and to consider restricting access to public STUN servers from devices that do not require them.
Looking ahead, researchers anticipate that attackers may refine the model, targeting other widely used protocols to expand the proxy infrastructure. The emergence of ClingSTUN underscores the broader challenge of securing a rapidly expanding IoT ecosystem, where even seemingly benign services can be weaponized when combined with outdated hardware. Continued collaboration between manufacturers, standards bodies, and security researchers will be essential to curb the spread of such proxy‑based malware.
Comments (0)
Be the first to comment.
Join the discussion