CLINGSTUN is a Linux backdoor that turns unpatched IoT and edge devices into remotely controllable proxy nodes. The malware uses legitimate public STUN infrastructure to punch through NAT, making its traffic appear as ordinary VoIP or WebRTC activity. FortiGuard Labs observed the operation unfold in three stages, each stage introducing a new download server. Initial access targeted a flaw in Hytec Inter routers (CVE-2022-36553); subsequent stages added bugs in EnGenius cloud services and D-Link UPnP.
The campaign has since expanded to include flaws in TP-Link Archer AX21 routers, Realtek SDKs, AVTECH cameras, Ivanti Connect Secure, and others. Some exploits are older; for example, the TP-Link CVE-2023-1389 was noted by CISA as part of exploited weaknesses dating back to May 2023.
The infection chain begins with a small script that downloads ClingSTUN builds for ARM, MIPS and x86, followed by disabling the hardware watchdog to resist reboots and wiping. It hides by placing copies in hidden files, inserting boot scripts, and blanking its command line to evade process lists. With root access, it further masks itself by copying process details from init.
ClingSTUN can self-spread by carrying exploits for additional vulnerabilities in Realtek, MVPower, TBK DVRs, Linksys, LB-LINK, China Mobile and KGUARD devices. For command-and-control, it issues STUN requests to multiple public servers to retain NAT paths, awaiting a 20-byte trigger to spread or receive a remote command via a separate TCP connection. FortiGuard notes that STUN servers are legitimate infrastructure and cautions that exploitation status remains “unverified” for device mappings.
Practical response centres on patching, inventorying internet-facing devices, disabling unnecessary exposed services, and monitoring unusual STUN or boot-script activity.