ClingSTUN Malware Turns Vulnerable IoT Devices Into Persistent Remote Proxy Nodes
ClingSTUN exploits unpatched IoT devices and turns them into persistent proxy nodes using public STUN.
FortiGuard documented ClingSTUN, a Linux backdoor that exploits unpatched internet-facing devices and turns them into persistent proxy nodes, using public STUN so traffic resembles VoIP or WebRTC. Activity expanded from Hytec Inter routers via CVE-2022-36553 to EnGenius CVE-2025-34035, D-Link UPnP CVE-2024-23625, and TP-Link Archer AX21 CVE-2023-1389, plus Realtek, AVTECH, Linear, Ivanti, and Tenda devices. Multi-architecture payloads persist through init scripts, hide as .cling, conceal process data, kill competing processes, and can propagate with seven embedded exploits. CISA added CVE-2023-1389 to the Known Exploited Vulnerabilities catalog in 2023.
- ClingSTUN turns exploited Linux IoT devices into persistent proxy nodes.
- Access used command injection, including CVE-2022-36553 and CVE-2023-1389.
- It persists through init scripts and hides .cling binaries and process data.
- Public STUN requests make traffic resemble ordinary VoIP or WebRTC.
- Seven embedded exploits support self-propagation to more device types.
Vulnerabilities mentionedAll →
- CVE-2022-365539.891%Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgipublished · hytec hwl-2511-ss firmware
- CVE-2023-13898.8100%Command Injection in TP-Link Archer AX21 Router Allows Remote Code Execution
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha256 | 4fbd61cb9181ebbc4fe9a6e59d3c346dc00001da48d66bd890556fc6fad22b07 | d411afc0f150f8f6f30e470a77204de87e3b0815fa9bb8a84 File hash 4fbd61cb9181ebbc4fe9a6e59d3c346dc00001da48d66bd890556fc6fad22b07 Note: IP addresses and domains are intentionally defanged ( |
| sha256 | a297eddfa7abea8d411afc0f150f8f6f30e470a77204de87e3b0815fa9bb8a84 | a1e61e808511387373d8d120348b5be0929621d21e6e9946a File hash a297eddfa7abea8d411afc0f150f8f6f30e470a77204de87e3b0815fa9bb8a84 File hash 4fbd61cb9181ebbc4fe9a6e59d3c346dc00001da48d66bd89 |
| sha256 | dc892f5013edb0aa1e61e808511387373d8d120348b5be0929621d21e6e9946a | t 222[.]223[.]152[.]97 Host 118[.]145[.]196[.]225 File hash dc892f5013edb0aa1e61e808511387373d8d120348b5be0929621d21e6e9946a File hash a297eddfa7abea8d411afc0f150f8f6f30e470a77204de87e |
Full article622 words · extracted from gbhackers.com · click to collapse
ClingSTUN, a Linux backdoor that exploits unpatched internet-facing devices and converts them into persistent, remotely controlled proxy nodes.
The malware combines startup persistence, process concealment, competitor termination, and remote command execution with legitimate STUN infrastructure to support connectivity through network address translation.
The research published October 5 documents three campaign periods with changing payload servers and expanding exploitation capabilities.
Its defining feature is not a new vulnerability, but the integration of established exploitation techniques with public NAT-traversal services, allowing malicious communications to resemble ordinary VoIP and WebRTC traffic.
That distribution phase lasted two days before the attacker switched to 222[.]223[.]152[.]97. The latest observed download source was 118[.]145[.]196[.]225.
Subsequent activity targeted EnGenius cloud services through CVE-2025-34035 and D-Link UPnP through CVE-2024-23625, before broadening to Realtek SDK, TP-Link Archer AX21, AVTECH cameras, Linear access-control systems, and additional devices.

FortiGuard said in a report shared with GBhackers, the initial campaign delivered ClingSTUN from 124[.]163[.]212[.]119 through CVE-2022-36553, a command injection vulnerability affecting Hytec Inter HWL-2511-SS routers.
The expanding exploit set also included Ivanti appliances and Tenda equipment.
ClingSTUN Malware
One targeted vulnerability, CVE-2023-1389, enables unauthenticated command injection on vulnerable TP-Link Archer AX21 firmware.
CISA added it to its Known Exploited Vulnerabilities catalog on May 1, 2023, underscoring how previously documented weaknesses remain useful entry points for evolving malware campaigns.
Early downloaders execute architecture-specific payloads supporting ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64.
The third downloader adds aggressive cleanup, inspecting mounted paths and terminating processes associated with suspicious mounts or executables under /tmp.

ClingSTUN disables watchdog timers through ioctl operations against /dev/watchdog and /dev/misc/watchdog.
It also enumerates /proc, examines executable paths and command lines, and kills selected processes, including potential competitors operating from temporary directories.
For persistence, the backdoor copies itself to /root/.cling and /usr/local/bin/.cling, assigns executable permissions, and modifies /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot to launch during startup.
The malware then clears its original command-line arguments.
When running as root, it copies selected metadata from /proc/1/ into /tmp and bind-mounts that directory over its own process entry, obscuring process information behind data associated with the init process.

ClingSTUN binds a UDP socket to a random local port and sends standard 20-byte STUN binding requests.
The second evolution contacts 24 public endpoints and requires at least half to succeed; the third reduces the set to 13 and requires every endpoint connection to succeed.
Afterward, it periodically transmits its group identifier and mapped-port list to those endpoints.
Researchers did not identify separate coordination-server registration in this path, and how operators obtain mappings and deliver control traffic through NAT remains unverified.
A 20-byte operator packet activates additional functionality. Command 1 initiates an outbound TCP connection to a supplied endpoint, retrieves a command, and executes it. Seven embedded exploits additionally support self-propagation.
Defenders should correlate unexpected STUN traffic with recurring UDP keepalives, startup-file changes, hidden .cling binaries, and unusual process mounts.
Legitimate public STUN servers are not inherently attacker-controlled indicators. Accurate inventories, timely firmware updates, and reduced internet exposure directly address the campaign’s enabling conditions.
IOCs
| Type | Indicator |
|---|---|
| Host | 124[.]163[.]212[.]119 |
| Host | 222[.]223[.]152[.]97 |
| Host | 118[.]145[.]196[.]225 |
| File hash | dc892f5013edb0aa1e61e808511387373d8d120348b5be0929621d21e6e9946a |
| File hash | a297eddfa7abea8d411afc0f150f8f6f30e470a77204de87e3b0815fa9bb8a84 |
| File hash | 4fbd61cb9181ebbc4fe9a6e59d3c346dc00001da48d66bd890556fc6fad22b07 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.