FORTINET’S FortiGuard Labs researchers have uncovered a Linux backdoor, dubbed ClingSTUN, that compromises IoT devices by exploiting at least 24 known vulnerabilities across a broad range of Internet-connected gear from vendors including Realtek, MVPower, TBK, Linksys, LB-LINK, China Mobile and KGUARD. The oldest flaw cited is CVE-2014-8361 in a Realtek device, while the most recent is CVE-2026-87827, a remote code execution flaw in a KGUARD DVR disclosed in 2026.
Attackers are observed in multiple waves using this evolving vulnerability chain to gain access to exposed devices and then establish persistence. FortiGuard notes that ClingSTUN also embeds hard-coded exploits for seven additional vulnerabilities to spread laterally to other vulnerable IoT systems.
What makes ClingSTUN particularly concerning is its use of legitimate public STUN servers to maintain connectivity with infected devices, effectively turning compromised endpoints into proxy nodes. The malware periodically reports to STUN servers to help determine how the device appears on the Internet and which ports are reachable, without a traditional command-and-control server being identified.
Researchers emphasise the risk of the infected device acting as an intermediary that can route traffic, potentially masking malicious activity under legitimate VoIP/WebRTC traffic and exposing organisations to IP blocklisting, bandwidth costs and operational disruption. Mitigation calls for accurate device inventories, prompt firmware updates and, where possible, removing direct Internet exposure or disabling vulnerable services.
Organisations should also restrict IoT access to trusted networks and monitor outbound communications for unusual STUN activity, unexpected UDP sockets, and recurring messages containing group identifiers and mapped-port lists.