Zero Day Room
Live
Vulnerabilities

ClingSTUN malware exploits 24 IoT flaws via STUN protocol

A new Linux backdoor named ClingSTUN hijacks internet-facing IoT devices by exploiting two dozen known, unpatched vulnerabilities.

A new Linux backdoor named ClingSTUN hijacks internet-facing IoT devices by exploiting two dozen known, unpatched...

A newly discovered Linux backdoor named ClingSTUN is exploiting two dozen known vulnerabilities in internet-facing IoT devices, turning them into proxies that blend with legitimate VoIP and WebRTC traffic. FortiGuard Labs identified the malware, which targets unpatched flaws across a wide range of brands to establish persistent remote access.

The malware targets two dozen vulnerabilities for initial access from brands including Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link. ClingSTUN also contains hard-coded exploits for self-propagation targeting seven additional vulnerabilities from China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK. The campaign was first observed across three distinct periods starting October 5, with attackers adding more entry points in the third phase.

Exploitation pattern across three campaign periods

The attack evolved significantly over three observed periods. The first period lasted just two days and exploited a single flaw, CVE-2022-36553 in Hytec Inter routers. In the second period, attackers switched to two different vulnerabilities: CVE-2025-34035 in EnGenius's IoT cloud service and CVE-2024-23625 in D-Link's UPnP service. The operators also spread the malware through command injection flaws in Linear, Realtek, TP-Link, AVTECH and D-Link devices.

The third period saw the most expansion. Included vulnerabilities are Ivanti Connect Secure flaws CVE-2023-46805 and CVE-2024-21887, and newer bugs such as CVE-2026-36356 and CVE-2025-67038. This brought FortiGuard's tracked list to 24 vulnerabilities.

Propagation, persistence, and remote control mechanics

ClingSTUN functions as a back-connect proxy that sends STUN binding requests to public servers to discover external address and port mappings. Because the STUN servers are legitimate, the traffic resembles normal VoIP and WebRTC communications. The malware supports remote command execution and carries hard-coded exploits for seven more vulnerabilities to spread itself.

For persistence, ClingSTUN copies itself to two hidden files with executable permissions and appends startup commands to three system initialization scripts. A restart will not remove ClingSTUN because its startup entries reload the malware during boot. Each variant can terminate processes associated with competing malware and interfere with the device's watchdog timer.

The malware listens for specific packets that allow operators to perform remote code execution and trigger the self-propagation mechanism. Those packets can instruct the infected device to execute commands or begin scanning for more vulnerable systems. Downloaders recovered during the investigation could install ClingSTUN on several processor architectures.

Architecture
AMD x86-64
ARM
Intel 80386
MIPS R3000
PowerPC

FortiGuard noted that how the operator obtains the mappings and pushes commands through NAT remains unverified.

Defensive guidance and industry response

FortiGuard urged organizations to inventory internet-facing devices, prioritize patches for actively exploited flaws and replace or isolate devices that no longer receive security updates. Organizations should identify internet-facing equipment, install available firmware updates and restrict services that do not require public access. Devices that have reached the end of vendor support should be isolated or replaced, particularly when known vulnerabilities remain exposed.

Security experts emphasized the need for layered defenses. Louis Eichenbaum, federal CTO at ColorTokens, warned that "ClingSTUN is another reminder that organizations cannot patch their way out of cyber risk" and argued for compensating controls like microsegmentation. John Gallagher, VP at IoT security firm Viakoo, argued that "Believing that network segmentation provides security is a flawed assumption" and advocated for automated firmware remediation across multivendor IoT fleets.

FortiGuard advised assessing STUN activity alongside suspicious processes, unexpected UDP connections and recurring keepalive traffic. The firm did not identify the operators, disclose the number of infected devices, or name any affected organizations.

Related coverage

More from Vulnerabilities