ClingSTUN, a Linux backdoor that exploits unpatched internet-facing devices and converts them into persistent, remotely controlled proxy nodes. The malware combines startup persistence, process concealment, competitor termination, and remote command execution with legitimate STUN infrastructure to support connectivity through network address translation. The research published October 5 documents three campaign periods with changing payload servers […]
Read the original article:
