securityaffairs.com 6 Oct 2026, 06:31 UTC

ClingSTUN Hijacks Public STUN Servers to Hide IoT Backdoor Traffic

ClingSTUN Hijacks Public STUN Servers to Hide IoT Backdoor Traffic

FORTINET has detailed ClingSTUN, a Linux backdoor that hijacks public STUN infrastructure to hide traffic and extend control over compromised devices. The campaign targets old, internet-facing IoT devices and expands beyond Hytec Inter routers to include vendors such as D-Link, TP-Link, Realtek and Linksys, plus several DVRs and cloud platforms.

Infected systems become remotely controlled proxy nodes, with traffic blending into normal VoIP and WebRTC activity because it uses standard STUN requests to discover externally mapped IP addresses and ports.

The malware drops a small downloader appropriate to the device’s architecture (ARM, MIPS, PowerPC and Intel) and first checks for other malware on the host. It then persists by copying itself to multiple locations and appending to several boot scripts, enabling survival across reboots. It also aggressively removes competing malware, disables the watchdog timer to prevent auto-reboots, and even masquerades as PID 1 by swapping process metadata to hinder simple process monitoring.

A notable feature is its use of public STUN endpoints to maintain connectivity; Fortinet notes the number of endpoints has varied (24 then reduced to 13) to improve reliability, with a single control datagram capable of triggering outbound connections to fetch commands. The malware also ships hardcoded exploits for seven additional vulnerabilities to spread further, effectively turning each infected device into a network scanner.

Fortinet urges organisations to maintain inventory of internet-facing devices, monitor firmware and support status, and promptly apply available updates, prioritising vulnerabilities already known to be exploited. SOURCE_UNAVAILABLE

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline