Skip to main content
Emerging ThreatsMalware & Ransomware

ClingSTUN Malware Exploits IoT Flaws to Create Proxy Networks

Dimly lit industrial area with scattered IoT devices and exposed circuit boards.

FortiGuard Labs' list now stands at 24 vulnerabilities.

How ClingSTUN turns unpatched IoT devices into proxy nodes

A Linux proxy backdoor that FortiGuard Labs dubbed "ClingSTUN" exploits known, unpatched flaws in internet-facing IoT devices to turn them into remotely controlled proxy nodes. The malware functions as a back-connect proxy: compromised devices send Session Traversal Utilities for NAT (STUN) binding requests to legitimate public STUN servers to discover external address and port mappings and to keep NAT bindings open. The infected hosts then periodically report group identifiers and mapped ports to those same servers.

Exploited flaws and the campaign timeline

FortiGuard tracked the campaign in three periods, each using a different download server. The first period lasted two days and relied on CVE-2022-36553 in Hytec Inter routers. In the second period attackers switched to two vulnerabilities: CVE-2025-34035 in EnGenius's IoT cloud service and CVE-2024-23625 in D-Link's UPnP service. They also spread the malware through command-injection flaws in Linear, Realtek, TP-Link, AVTECH and D-Link devices.

In a later third period the operators broadened their entry points. FortiGuard's list now includes 24 vulnerabilities overall, naming Ivanti Connect Secure flaws CVE-2023-46805 and CVE-2024-21887 and newer bugs such as CVE-2026-36356 and CVE-2025-67038. FortiGuard also said the malware carries hard-coded exploits for seven additional vulnerabilities, including flaws in Realtek's SDK and three DVR products.

STUN traffic and the camouflage of legitimate services

ClingSTUN abuses legitimate STUN infrastructure in a way that helps the traffic blend with normal VoIP and WebRTC communications. FortiGuard reported that the second version of the malware used 24 public STUN servers and the third used 13, and it emphasized that because those servers are legitimate the communications resemble expected real-time traffic.

FortiGuard also cautioned that exactly how the operator obtains the mappings and pushes commands through NAT "remains unverified," and warned against treating the STUN services as attacker-controlled infrastructure. That uncertainty leaves a central operational detail about the campaign unresolved in the published findings.

Persistence, evasion and propagation techniques

Once deployed, ClingSTUN takes multiple steps to maintain control of compromised devices. It kills competing processes and watchdog timers, copies itself into system locations, modifies boot scripts for persistence, and hides behind process information copied from the system's init process. The backdoor supports remote command execution and continues to try to spread by invoking its embedded exploits.

Containment trade-offs: segmentation versus automated remediation

Responses to ClingSTUN's risks split defenders on tactics. Louis Eichenbaum, federal CTO at ColorTokens, warned that "ClingSTUN is another reminder that organizations cannot patch their way out of cyber risk." He argued for compensating controls where immediate patching is not possible, recommending microsegmentation to limit lateral movement.

John Gallagher, VP at IoT security firm Viakoo, disagreed with that emphasis on segmentation. "Believing that network segmentation provides security is a flawed assumption," he said, arguing instead for automated firmware remediation across multivendor IoT fleets. "Visibility alone will not save you here," he added.

FortiGuard urged defenders to assess STUN activity alongside suspicious processes, unexpected UDP connections and recurring keepalive traffic. The firm also recommended that organizations inventory internet-facing devices, prioritize patches for actively exploited flaws, and replace or isolate devices that no longer receive security updates.

What this means for technologists, IoT fleet managers, and enterprises

  • Technologists and security teams: Watch for STUN binding requests and recurring keepalive traffic as potential indicators, and correlate those signals with unexpected UDP connections and suspicious processes on IoT hosts, per FortiGuard's guidance.
  • IoT fleet managers and procurement leaders: Inventory internet-facing devices and prioritize remediation for actively exploited CVEs listed by FortiGuard; consider replacing or isolating devices that no longer receive security updates.
  • Enterprise defenders and architects: Evaluate the trade-off between compensating controls such as microsegmentation, as Louis Eichenbaum recommends, and the push for automated firmware remediation across diverse device fleets urged by John Gallagher.

ClingSTUN illustrates a pragmatic adversary tactic: reuse known vulnerabilities, leverage legitimate infrastructure to mask command and control, and embed additional exploits to multiply infection paths. FortiGuard's October 5 research names concrete CVEs, affected vendors and detection cues — and it leaves one practical question hanging: how the operator reliably obtains NAT mappings and pushes commands through STUN-assisted channels remains unverified in the published account. That gap is the immediate technical unknown defenders will want to close while they inventory, patch and isolate exposed devices.

Original story