At a Glance
| Malware family | ClingSTUN, a Linux back-connect proxy backdoor |
| Threat actor | Unknown; no attribution |
| Targets | Internet-facing IoT and edge devices; victim counts not disclosed |
| Delivery vector | Exploitation of known flaws in D-Link, TP-Link, Realtek, Ivanti, Tenda, and other products |
| Key capabilities | STUN-based NAT traversal, boot persistence, process hiding, rival killing, remote commands, self-spreading |
| Sources | FortiGuard Labs; CISA |
TL;DR
ClingSTUN breaks into unpatched IoT devices and turns them into remotely controlled proxies. It uses legitimate public STUN servers to punch through NAT, so its traffic looks like normal VoIP or WebRTC. It can also spread itself to new devices.
Delivery
FortiGuard saw the campaign unfold in three phases, each with a new download server. It began with a flaw in Hytec Inter routers, CVE-2022-36553. Later, the operators added bugs in EnGenius cloud services and D-Link UPnP.

The list kept growing. It now includes flaws in TP-Link Archer AX21 routers, Realtek SDKs, AVTECH cameras, and Ivanti Connect Secure. Many are old. For example, CISA added the TP-Link bug, CVE-2023-1389, to its exploited-flaws catalog back in May 2023. Mirai botnet operators abused it even then.
Infection Chain
Clearing the Ground
A small script first downloads ClingSTUN builds for several chip types, including ARM, MIPS, and x86. The newest version of that script also kills processes running from temp folders.
Once running, ClingSTUN disables the device’s hardware watchdog. That stops the device from rebooting and wiping the infection. Next, it hunts for rival malware and kills any suspicious process.
Staying Hidden
The malware copies itself into hidden files and adds them to the device’s boot scripts. It then blanks its own command line, so it shows up empty in process lists. With root access, it goes further. It covers its own process details with information copied from the system’s init process.
Spreading on Its Own
ClingSTUN also carries exploits for seven more flaws. These target Realtek, MVPower and TBK DVRs, Linksys, LB-LINK, China Mobile, and KGUARD devices. As a result, every infected device can help find the next victim.
Command-and-Control and Data Exfiltration
STUN helps apps learn their public IP address behind a NAT router. ClingSTUN sends standard STUN requests to 24 public servers in older builds and 13 in newer ones. This keeps NAT paths open so operators can reach the device.
The backdoor then waits for a special 20-byte packet. That packet can trigger self-spreading or a remote command. For commands, ClingSTUN opens a separate TCP connection, fetches the instruction, and runs it.
FortiGuard admits gaps in its picture. How operators learn each device’s external mapping “remains unverified.” It also warns that the STUN servers belong to legitimate services and “should not be automatically classified as attacker-controlled infrastructure.”
Defense and Detection Guidance
The ClingSTUN backdoor depends on poor patching. FortiGuard calls this a lesson in “consistent cyber hygiene.” Defenders should:
- Inventory internet-facing devices and track their firmware and support status.
- Patch actively exploited flaws first, such as those in CISA’s catalog.
- Replace or isolate devices that no longer receive updates.
- Close unneeded exposed services like UPnP and remote admin panels.
- Flag STUN traffic from devices that do not handle voice or video calls.
- Check boot scripts for hidden entries and watch for repeated UDP keepalives.
Finally, remember that a proxy node may not harm its owner directly. Instead, it lends attackers a clean address to hide behind.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!