FORTIGUARD Labs has tracked a Linux proxy backdoor dubbed ClingSTUN, which targets unpatched internet-facing IoT devices and uses legitimate public STUN servers to keep compromised systems reachable as remotely controlled proxy nodes. The campaign unfolded in three periods, each with different download servers. The first used a single flaw, CVE-2022-36553 in Hytec Inter routers.
In the second phase, attackers weaponised CVE-2025-34035 in EnGenius’s IoT cloud service and CVE-2024-23625 in D-Link’s UPnP service, then spread via command-injection flaws in Linear, Realtek, TP-Link, AVTECH and D-Link devices. In the third period, the operators added more entry points, with FortiGuard listing 24 vulnerabilities in total, including Ivanti Connect Secure flaws CVE-2023-46805 and CVE-2024-21887 and newer bugs such as CVE-2026-36356 and CVE-2025-67038.
ClingSTUN’s operation disguises its activity as normal VoIP/WebRTC traffic by sending STUN binding requests to public servers (13–24 servers across versions) to reveal external mappings and keep NAT bindings open, then periodically reporting a group identifier and mapped ports. The malware exhibits persistence and dominance behaviours—killing competing processes and watchdog timers, copying itself into system locations, modifying boot scripts, and hiding behind init process data.
It supports remote command execution and ships hard-coded exploits for seven additional flaws, including weaknesses in Realtek’s SDK and several DVR products. FortiGuard cautions that the STUN infrastructure may appear legitimate, so organisations should treat these services cautiously rather than assuming they are attacker-controlled.
Experts offer practical responses centred on containment and patching: inventory internet-facing devices, prioritise patches for actively exploited flaws, and either replace or isolate devices that no longer receive security updates. Compensating controls, such as microsegmentation, are advised for devices that cannot be fixed immediately, while automated firmware remediation across multivendor IoT fleets is championed by some researchers. FortiGuard also recommends monitoring STUN activity alongside suspicious processes, unusual UDP connections and recurring keepalive traffic.