ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes
ClingSTUN exploits unpatched IoT flaws and uses public STUN servers to run proxy nodes.
FortiGuard Labs reported ClingSTUN, a Linux proxy backdoor observed exploiting unpatched flaws in internet-facing IoT devices and turning them into remotely controlled proxy nodes. The campaign used three phases and download servers, beginning with CVE-2022-36553 in Hytec Inter routers, then CVE-2025-34035 in EnGenius and CVE-2024-23625 in D-Link, before expanding to 24 vulnerabilities including Ivanti Connect Secure flaws CVE-2023-46805 and CVE-2024-21887 plus CVE-2026-36356 and CVE-2025-67038. ClingSTUN sends STUN binding requests to legitimate public servers so traffic resembles VoIP or WebRTC, reports mapped ports, kills competing processes, persists via boot scripts, masquerades using init process information, and supports remote command execution. It also carries exploits for seven additional vulnerabilities, including flaws in Realtek's SDK and DVR products, to spread.