ClingSTUN Linux Backdoor Turns Vulnerable IoT Devices Into Proxies
FortiGuard Labs says ClingSTUN, a Linux backdoor, exploits known IoT flaws and uses public STUN servers to create persistent proxy nodes.
FortiGuard Labs, in an October 5, 2026 analysis, described ClingSTUN, a Linux back-connect proxy backdoor that infects internet-facing routers, cameras, DVRs, and other IoT devices and turns them into remotely controlled proxy nodes. Operators have used known command-injection, code-injection, and buffer-overflow flaws, including CVE-2022-36553 on Hytec Inter, CVE-2025-34035 on EnGenius, CVE-2024-23625 on D-Link, CVE-2023-1389 on TP-Link Archer AX21, and CVE-2024-7029 on AVTECH, with further activity reported against Realtek, Ivanti, Tenda, Linksys, Linear, and others; the malware also carries seven built-in exploits to spread. Dark Reading says it exploits 24 known flaws, while other reports describe dozens of device flaws or more than a dozen vendors plus those seven exploits, and no source published an infection count or confirmed victim list. Downloaders deliver ARM, MIPS, PowerPC, Intel 80386/x86, and AMD x86-64 builds; the malware persists through init or rc scripts, hides copies (reported as .cling and, in one account, as PID 1), kills rival processes, disables a watchdog, and can accept an operator packet—described by one outlet as 20 bytes—to run commands or propagate. It uses legitimate public STUN servers for NAT mapping so traffic resembles VoIP or WebRTC; Fortinet says those servers are not compromised and urges patching exposed devices. CISA added CVE-2023-1389 to its Known Exploited Vulnerabilities catalog in 2023.
- FortiGuard Labs' October 5, 2026 analysis describes ClingSTUN, a Linux back-connect proxy backdoor.
- It turns infected routers, cameras, DVRs, and other IoT devices into proxy nodes via legitimate public STUN servers that Fortinet says are not compromised.
- Named flaws include CVE-2022-36553 (Hytec), CVE-2025-34035 (EnGenius), CVE-2024-23625 (D-Link), CVE-2023-1389 (TP-Link Archer AX21), and CVE-2024-7029 (AVTECH); CISA added CVE-2023-1389 to the KEV catalog in 2023.
- Sources disagree on scale: Dark Reading cites 24 known flaws, while others describe flaws across more than a dozen vendors plus seven hardcoded exploits for self-propagation.
- Payloads cover ARM, MIPS R3000, PowerPC, Intel 80386/x86, and AMD x86-64.
- It persists through init or rc scripts, hides copies, kills rival processes, and disables a watchdog; one report says a 20-byte packet triggers commands or spread.
- No report gave an infection count or confirmed victim list; Fortinet urges patching exposed devices.
Coverage timelineoldest first · each row is one article
- · 5d agoLinux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
SecurityWeek· 74
FortiGuard Labs says ClingSTUN Linux backdoor abuses STUN and exploits dozens of device flaws to spread.
- · 5d agoClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
Dark Reading· 52
ClingSTUN, a Linux backdoor, exploits 24 known flaws and turns IoT devices into proxies via public STUN servers.
- · 4d agoClingSTUN Malware Turns Vulnerable IoT Devices Into Persistent Remote Proxy Nodes
GBHackers· 68
ClingSTUN exploits unpatched IoT devices and turns them into persistent proxy nodes using public STUN.
Vulnerabilities in this storyAll →
- CVE-2022-365539.891%Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgipublished · hytec hwl-2511-ss firmware
- CVE-2023-13898.8100%Command Injection in TP-Link Archer AX21 Router Allows Remote Code Execution