Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical OpenAI Sandbox Flaw Exposed Paid AI Models
October 7, 2026
Critical Progress DataDirect GenAI Flaw Lets OpenAPI Files Execute OS Commands
October 7, 2026
Critical Rejetto HFS Flaw CVE-2024-23652 Lets Attackers Forge Admin Sessions
October 7, 2026
Home/Threats/ClingSTUN Backdoor Exploits IoT Vulnerabilities for Persistent Remote Access
Threats

ClingSTUN Backdoor Exploits IoT Vulnerabilities for Persistent Remote Access

Key Takeaways ClingSTUN is a sophisticated Linux backdoor that targets vulnerable IoT devices to establish persistent remote access. The malware transforms compromised devices into proxy nodes for...

David kimber
David kimber
October 6, 2026 4 Min Read
13 0

Key Takeaways

  • ClingSTUN is a sophisticated Linux backdoor that targets vulnerable IoT devices to establish persistent remote access.
  • The malware transforms compromised devices into proxy nodes for traffic relay and remote command execution, rather than just simple infections.
  • ClingSTUN actively exploits known vulnerabilities across multiple vendors, including Hytec, EnGenius, D-Link, Realtek, Linear, TP-Link, and AVTECH.
  • It employs advanced stealth techniques, such as process concealment and abuse of public STUN services, to evade detection and maintain control.
  • Organizations must prioritize patching, inventory management, and network monitoring to defend against this evolving threat.

A new Linux-based backdoor, dubbed ClingSTUN, is actively exploiting vulnerabilities in Internet of Things (IoT) devices to secure persistent remote access for attackers. Unlike many IoT malware strains that merely infect devices, ClingSTUN converts compromised hardware into a network of remotely controlled proxy nodes capable of relaying traffic and executing arbitrary commands. The campaign demonstrates an adaptable attack methodology, continuously expanding its targeting to include a wider range of vulnerable products and known security flaws.

Table Of Content

  • Key Takeaways
  • ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities
  • Public STUN Services Conceal Connectivity
  • What You Should Do

Security researchers at Fortinet have detailed this high-severity threat in a report released on October 5. Their analysis, shared with Cyber Security News (CSN), highlights how ClingSTUN leverages a combination of vulnerability exploitation, robust startup persistence mechanisms, and the abuse of public networking services to maintain its foothold on infected Linux devices. While the report does not disclose specific infection numbers or confirmed victim lists, it underscores the significant risk posed by ordinary connected equipment being weaponized into persistent attack infrastructure, with potential ramifications extending far beyond the initially compromised device.

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities

The ClingSTUN campaign has evolved through at least three distinct stages, each characterized by changes in its download infrastructure and a broadened exploitation strategy. Initially, researchers observed the backdoor being delivered by exploiting CVE-2022-36553, a command injection vulnerability found in Hytec Inter HWL-2511-SS routers. This initial phase was short-lived, lasting only two days before the threat actors shifted tactics.

The second stage of the campaign expanded its reach by targeting additional vulnerabilities, including CVE-2025-34035 in EnGenius cloud services and CVE-2024-23625, a UPnP flaw in D-Link devices. Subsequent activity demonstrated an even broader targeting strategy, encompassing devices from Realtek, Linear, TP-Link, and AVTECH, among others. This indicates the operators’ strategy of not relying on a single vendor or point of entry.

One notable vulnerability exploited is CVE-2023-1389 in TP-Link Archer AX21 routers, a flaw previously documented in other command injection attacks. This highlights how unpatched, familiar vulnerabilities continue to serve as effective entry points for attackers. Additionally, the campaign exploited CVE-2024-7029 in AVTECH AVM1203 cameras, a vulnerability previously linked to Mirai botnet attacks. It is important to note that while the vulnerabilities overlap, there is no direct evidence to suggest ClingSTUN is part of the Mirai family or operated by the same threat actors.

ClingSTUN downloaders are highly versatile, retrieving versions tailored for various architectures, including ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64 systems. The most recent iteration of the downloader includes additional defensive measures, such as removing specific process-related mounts and terminating processes running from temporary storage. These actions help to clear out any competing malware or processes that might interfere with the backdoor’s establishment.

Once established, ClingSTUN ensures persistence by creating hidden executable copies and modifying three critical startup files on the infected system, guaranteeing its execution during every boot sequence. Furthermore, it disables watchdog timers and terminates selected processes, effectively combining its persistence mechanisms with tactics to suppress rival programs or system monitoring tools on the compromised device.

Public STUN Services Conceal Connectivity

To further enhance its stealth capabilities, ClingSTUN employs sophisticated process concealment techniques. It clears its command-line arguments, rendering standard process listings uninformative. When operating with elevated administrator privileges, the backdoor overlays its process information with metadata copied directly from the system’s initial process. This mimicry makes it challenging for defenders to distinguish malicious processes from legitimate ones based on superficial inspection, underscoring the need for deeper analysis.

A key aspect of ClingSTUN’s operational security is its use of STUN (Session Traversal Utilities for NAT) protocol to discover external IP addresses and port mappings. STUN, commonly employed in VoIP and web communications, is abused by the backdoor to facilitate covert command and control (C2) communications. Fortinet’s analysis revealed that the second version of the malware contacted 24 public STUN endpoints, while the third version reduced this to 13, requiring successful connections to all of them to operate.

The backdoor can be activated by a small, 20-byte operator packet, enabling remote command execution or self-propagation. One specific command directs the malware to establish an outbound TCP connection to a designated endpoint, where it subsequently receives further instructions. Researchers have identified seven built-in vulnerability exploits within ClingSTUN, designed to facilitate its spread to other routers and recording equipment. However, Fortinet researchers were unable to fully verify how operators obtain external mappings and deliver control traffic through network address translation (NAT).

It is crucial to understand that public STUN servers are not inherently malicious. Instead, defenders should correlate connections to these services with other suspicious activities, such as unusual UDP traffic, unexpected processes, and recurring keepalive signals, to identify potentially infected devices.

What You Should Do

  • Inventory and Monitor Devices: Maintain a comprehensive inventory of all internet-facing devices, especially IoT equipment. Regularly audit and monitor

    Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

    Tags:

    AttackCVEExploitMalwarePatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Google Android 17 Gets 6 Advanced Protection Features

Next Post

FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Pwn2Own 2026 Sees 32 Zero-Days Exploit Samsung S26, Pixel 10, OpenAI Codex
October 7, 2026
Critical OpenSSH Flaws Allow Plaintext Recovery, File Write, and Injection
October 7, 2026
Critical WordPress Flaws Allow XSS, SQL Injection, Data Disclosure
October 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us