
Hiding where defenders may not look
ClingSTUN was found targeting a wide range of products, including Hytec routers, EnGenius IoT services, D-Link devices, TP-Link Archer AX21 routers, AVTECH cameras and other equipment. The researchers said the malware currently has multiple known entry points and continues to evolve, with additional vulnerabilities being incorporated into the attack chain.
“Updates take time to test and deploy, some operational and IoT devices cannot be taken offline easily, and many legacy products are no longer supported by their manufacturers,” Eichenbaum noted. “Attackers understand this reality and continue targeting known vulnerabilities because those weaknesses remain effective.”
Once installed, ClingSTUN takes steps to make removal and detection more difficult. It copies itself to hidden locations, adds entries to /etc/inittab, /etc/init.d/rcs, and /etc/rc.d/rc.boot to launch at startup, kills competing processes, and disables the watchdog timer.
It can also hide its process information by making its “/proc” entry resemble the system’s init process, the researchers said in a blog post.
