Post

ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes

ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes

ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes

A Linux proxy backdoor has been observed exploiting known, unpatched flaws in internet-facing IoT devices and abusing legitimate public STUN servers to keep compromised systems reachable as remotely controlled proxy nodes. FortiGuard Labs, which dubbed the malware ClingSTUN, said in research published on October 5 that it tracked the campaign across three periods, each with a different download server.

Campaign Overview

  • First Period: Lasted two days and relied on a single flaw, CVE-2022-36553 in Hytec Inter routers.
  • Second Period: Attackers switched to two vulnerabilities: CVE-2025-34035 in EnGenius’s IoT cloud service and CVE-2024-23625 in D-Link’s UPnP service.
  • Third Period: More entry points were added, with FortiGuard’s list now standing at 24 vulnerabilities, including Ivanti Connect Secure flaws CVE-2023-46805 and CVE-2024-21887, along with newer bugs such as CVE-2026-36356 and CVE-2025-67038.

How ClingSTUN Works

ClingSTUN operates as a back-connect proxy. It sends STUN binding requests to public servers (24 in the second version and 13 in the third) to discover its external address and port mappings, keeping NAT bindings open. It periodically reports its group identifier and mapped ports to the same servers. Because the servers are legitimate, the traffic resembles normal VoIP and WebRTC communications.

FortiGuard noted that how the operator obtains the mappings and pushes commands through NAT remains unverified. They warned against treating the STUN services as attacker-controlled infrastructure. The malware kills competing processes and watchdog timers, copies itself into system locations, modifies boot scripts for persistence, and hides behind process information copied from the system’s init process. It supports remote command execution and carries hard-coded exploits for seven more vulnerabilities, including flaws in Realtek’s SDK and three DVR products, to spread itself.

Recommendations

FortiGuard advised assessing STUN activity alongside suspicious processes, unexpected UDP connections, and recurring keepalive traffic. The cybersecurity firm also urged organizations to:

  • Inventory internet-facing devices.
  • Prioritize patches for actively exploited flaws.
  • Replace or isolate devices that no longer receive security updates.

For more details, Read full article!

This post is licensed under CC BY 4.0 by the author.