Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

ClingSTUN: A Linux Backdoor Exploiting Public STUN Infrastructure to Route Traffic Past NAT




A new Linux malware family, dubbed ClingSTUN, has been identified by Fortinet as a back-connect proxy backdoor that exploits unpatched IoT devices and public STUN servers to route traffic past NAT systems. The malware takes advantage of vulnerabilities in over a dozen vendors, including D-Link, TP-Link, and Realtek, and can turn infected systems into remotely controlled proxy nodes. With its persistence mechanism, ClingSTUN can survive a reboot and continues to operate, making it a significant threat to organizations with Internet-facing devices. By understanding the tactics, techniques, and procedures of this malware, organizations can take steps to improve their cyber hygiene and protect themselves against this type of attack.

  • ClingSTUN is a Linux malware family identified as a back-connect proxy backdoor, turning infected systems into proxy nodes.
  • The malware exploits unpatched vulnerabilities in IoT devices and public STUN servers to achieve its goals.
  • The attackers target devices from over a dozen vendors, including old, unpatched devices exposed to the internet.
  • The malware has a persistence mechanism that copies itself into boot scripts and kills suspicious processes.
  • The malware uses STUN servers to hide its activity in normal network traffic.
  • Command delivery requires a human operator to send a packet to the malware.
  • The malware carries hardcoded exploits to spread itself further.
  • Fortinet stresses the importance of consistent cyber hygiene to prevent exploitation of known vulnerabilities.



  • ClingSTUN is a Linux malware family that has been identified by Fortinet as a back-connect proxy backdoor. This type of malware can turn infected systems into remotely controlled proxy nodes, allowing attackers to route traffic past Network Address Translation (NAT) systems. The malware takes advantage of unpatched vulnerabilities in IoT devices and public STUN (Session Traversal Utilities for NAT) servers to achieve its goals.

    The attack starts with a familiar problem: old, unpatched devices exposed to the internet. Fortinet first spotted the campaign exploiting a known command injection flaw in Hytec Inter routers. As the campaign evolved, the attackers changed their download infrastructure and expanded the list of vulnerabilities they were exploiting.

    In the latest wave, they were targeting devices from more than a dozen vendors, including D-Link, TP-Link, Realtek and Linksys, as well as several DVR and IoT cloud platforms. Many of these devices are easy targets because they are rarely updated or closely monitored.

    Once the attackers find a vulnerable device, a small downloader script installs the right malware version for its hardware. The malware supports common architectures such as ARM, MIPS, PowerPC and Intel. The latest version also checks the device for other malware before installing itself. It scans mounted filesystems and kills suspicious processes running from temporary directories.

    The persistence mechanism is almost old-fashioned in its simplicity. The malware copies itself into two separate locations, then appends itself to three different boot scripts so it survives a reboot no matter which startup path the device actually uses. It also walks through every running process, checks whether the command line matches what the process claims to be, and kills anything that doesn’t line up.

    Two details stand out as genuinely well thought through rather than copy-pasted from some other botnet’s source code. First, it opens the device’s watchdog timer and quietly disables it, so the device never auto-reboots itself out of the infection the way embedded hardware is designed to if something goes wrong. Second, once it’s running as root, it swaps its own process metadata for a copy of PID 1’s, the very first process the kernel starts, which makes a basic process listing show what looks like the init system instead of malware.

    The STUN part is especially interesting because it helps ClingSTUN hide in normal network traffic. The malware sends standard requests to public STUN servers to find out its external IP address and port. These are the same services commonly used by VoIP and WebRTC applications. Later versions reduced the number of STUN servers and required all connections to work, which suggests the attackers were improving reliability. Because the traffic goes to legitimate third-party services, it can be difficult for defenders to tell the difference between ClingSTUN activity and normal traffic from apps such as Zoom.

    Command delivery itself still needs a human on the other end willing to send a 20-byte packet the right way. ClingSTUN establishes a UDP socket, binds to a random local port, and sends standard 20-byte STUN binding requests. It sends these to 24 public endpoints and ensures at least half succeed. The third evolution reduced this to 13 endpoints and ensures every endpoint connection succeeds.

    A single control datagram can trigger ClingSTUN to open a fresh outbound TCP connection to an address the operator specifies, pull down a command over that connection, and execute it, which keeps the heavy lifting off the STUN channel and limits what shows up in any one place. The malware also carries hardcoded exploits for seven more vulnerabilities purely for spreading itself further, meaning every infected device doubles as a scanner looking for its next host.

    Fortinet stresses that the STUN servers are not compromised or malicious. They are simply working as intended. These third-party services should not automatically be treated as attacker-controlled infrastructure. The report concludes that the exploitation of known, unpatched vulnerabilities reinforces the importance of consistent cyber hygiene. Organizations should inventory Internet-facing devices, track their firmware and support status, and promptly apply available security updates, prioritizing vulnerabilities known to be actively exploited.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/ClingSTUN-A-Linux-Backdoor-Exploiting-Public-STUN-Infrastructure-to-Route-Traffic-Past-NAT-ehn.shtml

  • https://securityaffairs.com/200450/uncategorized/clingstun-linux-backdoor-abuses-public-stun-infrastructure.html


  • Published: Tue Oct 6 02:42:58 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us