ClingSTUN Malware Turns Vulnerable IoT Devices Into Persistent Remote Proxy Nodes
ClingSTUN exploits unpatched IoT devices and turns them into persistent proxy nodes using public STUN.
FortiGuard documented ClingSTUN, a Linux backdoor that exploits unpatched internet-facing devices and turns them into persistent proxy nodes, using public STUN so traffic resembles VoIP or WebRTC. Activity expanded from Hytec Inter routers via CVE-2022-36553 to EnGenius CVE-2025-34035, D-Link UPnP CVE-2024-23625, and TP-Link Archer AX21 CVE-2023-1389, plus Realtek, AVTECH, Linear, Ivanti, and Tenda devices. Multi-architecture payloads persist through init scripts, hide as .cling, conceal process data, kill competing processes, and can propagate with seven embedded exploits. CISA added CVE-2023-1389 to the Known Exploited Vulnerabilities catalog in 2023.