Summary
- ClingSTUN exploits known vulnerabilities across routers, IoT equipment and other internet-facing devices.
- Compromised systems become remotely controlled proxy nodes and can execute commands for the operator.
- The malware uses legitimate public STUN services to discover external mappings and maintain connectivity through NAT.
A Linux backdoor is exploiting known vulnerabilities across internet-facing routers and embedded devices before turning compromised systems into remotely controlled proxy nodes that communicate through legitimate public internet infrastructure.
FortiGuard Labs has named the malware ClingSTUN and says its operators have repeatedly changed their initial access methods as they look for exposed equipment running vulnerable software.
Researchers observed exploitation across products from vendors including EnGenius, D-Link, Realtek, TP-Link, Ivanti, Lantronix, Tenda and others. Most of the weaknesses are already known and patched, placing the campaign’s success largely on systems that remain exposed with outdated firmware or vulnerable services.
Once installed, ClingSTUN operates as a back-connect proxy backdoor, allowing an infected device to relay traffic and receive commands from its operator. The malware also establishes boot persistence, interferes with watchdog functions, kills competing processes and can execute remote commands.
Its use of Session Traversal Utilities for NAT gives the campaign an unusual networking characteristic. STUN is a legitimate protocol used by applications such as voice and video services to determine the external IP address and port assigned to a device sitting behind network address translation.
ClingSTUN sends binding requests to public STUN endpoints so that it can learn those external mappings and keep the corresponding NAT bindings alive. Because many of the contacted servers are legitimate public services, the resulting traffic can resemble ordinary VoIP or WebRTC communication.
FortiGuard therefore cautions against assuming that third-party STUN servers contacted by an infected device are themselves attacker controlled. The suspicious behaviour emerges from the malware’s use of the service rather than from the public infrastructure simply existing.
That makes detection more complicated than blocking a known malicious domain. Security teams have to consider network behaviour alongside process activity, unexpected UDP communication, persistence mechanisms and other signs that an embedded Linux device is acting differently from its intended function.
The malware copies itself into hidden executable locations and modifies startup files so that it runs again after a reboot. Researchers also observed techniques intended to interfere with competing malware and make the ClingSTUN process harder to inspect.
Multiple builds support ARM, MIPS, PowerPC and x86 architectures, reflecting the fragmented hardware landscape across routers and IoT devices. Unlike a conventional corporate laptop estate, embedded environments can contain equipment from many vendors with different processors, support cycles and update mechanisms.
That diversity helps old vulnerabilities remain useful to attackers. A security flaw does not stop providing access when a patch becomes available if deployed equipment is never updated, cannot receive a current firmware image or exposes an unnecessary management service directly to the internet.
FortiGuard’s analysis shows the campaign changing its entry points over time rather than depending on a single vulnerability. ClingSTUN also contains hard-coded exploits used for self-propagation after the initial device has been compromised.
Organisational ownership can make those systems difficult to manage. Branch networking equipment, cameras, access systems and other embedded devices may sit outside the endpoint and server inventories used by central security teams, even though they retain direct internet exposure.
The backdoor’s proxy capability gives each compromised device value beyond the device itself because attacker traffic can subsequently be routed through an IP address belonging to the victim. That infrastructure can obscure the true source of later activity or support operations against unrelated targets.
FortiGuard has not fully established how operators obtain every external STUN mapping and deliver control traffic through NAT, leaving part of the control architecture unresolved. Researchers have nevertheless confirmed the malware’s persistence, proxy behaviour, remote command execution and continuing exploitation of known flaws.
ClingSTUN therefore combines two enduring infrastructure problems: internet-facing devices left on vulnerable software and malicious activity hidden among protocols and services that also have legitimate operational uses.





