Cyber Security News

ClingSTUN Malware Turns Vulnerable IoT Devices Into Persistent Remote Proxy Nodes

ClingSTUN, a Linux backdoor that exploits unpatched internet-facing devices and converts them into persistent, remotely controlled proxy nodes.

The malware combines startup persistence, process concealment, competitor termination, and remote command execution with legitimate STUN infrastructure to support connectivity through network address translation.

The research published October 5 documents three campaign periods with changing payload servers and expanding exploitation capabilities.

Its defining feature is not a new vulnerability, but the integration of established exploitation techniques with public NAT-traversal services, allowing malicious communications to resemble ordinary VoIP and WebRTC traffic.

That distribution phase lasted two days before the attacker switched to 222[.]223[.]152[.]97. The latest observed download source was 118[.]145[.]196[.]225.

Subsequent activity targeted EnGenius cloud services through CVE-2025-34035 and D-Link UPnP through CVE-2024-23625, before broadening to Realtek SDK, TP-Link Archer AX21, AVTECH cameras, Linear access-control systems, and additional devices.

Initial access packet via EnGenius command injection (CVE-2025-34035)(Source : FortiGuard).

FortiGuard said in a report shared with GBhackers, the initial campaign delivered ClingSTUN from 124[.]163[.]212[.]119 through CVE-2022-36553, a command injection vulnerability affecting Hytec Inter HWL-2511-SS routers.

The expanding exploit set also included Ivanti appliances and Tenda equipment.

ClingSTUN Malware

One targeted vulnerability, CVE-2023-1389, enables unauthenticated command injection on vulnerable TP-Link Archer AX21 firmware.

CISA added it to its Known Exploited Vulnerabilities catalog on May 1, 2023, underscoring how previously documented weaknesses remain useful entry points for evolving malware campaigns.

Early downloaders execute architecture-specific payloads supporting ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64.

The third downloader adds aggressive cleanup, inspecting mounted paths and terminating processes associated with suspicious mounts or executables under /tmp.

Terminating the watchdog timer (Source : FortiGuard).

ClingSTUN disables watchdog timers through ioctl operations against /dev/watchdog and /dev/misc/watchdog.

It also enumerates /proc, examines executable paths and command lines, and kills selected processes, including potential competitors operating from temporary directories.

For persistence, the backdoor copies itself to /root/.cling and /usr/local/bin/.cling, assigns executable permissions, and modifies /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot to launch during startup.

The malware then clears its original command-line arguments.

When running as root, it copies selected metadata from /proc/1/ into /tmp and bind-mounts that directory over its own process entry, obscuring process information behind data associated with the init process.

STUN binding with public endpoint (Source : FortiGuard).

ClingSTUN binds a UDP socket to a random local port and sends standard 20-byte STUN binding requests.

The second evolution contacts 24 public endpoints and requires at least half to succeed; the third reduces the set to 13 and requires every endpoint connection to succeed.

Afterward, it periodically transmits its group identifier and mapped-port list to those endpoints.

Researchers did not identify separate coordination-server registration in this path, and how operators obtain mappings and deliver control traffic through NAT remains unverified.

A 20-byte operator packet activates additional functionality. Command 1 initiates an outbound TCP connection to a supplied endpoint, retrieves a command, and executes it. Seven embedded exploits additionally support self-propagation.

Defenders should correlate unexpected STUN traffic with recurring UDP keepalives, startup-file changes, hidden .cling binaries, and unusual process mounts.

Legitimate public STUN servers are not inherently attacker-controlled indicators. Accurate inventories, timely firmware updates, and reduced internet exposure directly address the campaign’s enabling conditions.

IOCs

TypeIndicator
Host124[.]163[.]212[.]119
Host222[.]223[.]152[.]97
Host118[.]145[.]196[.]225
File hashdc892f5013edb0aa1e61e808511387373d8d120348b5be0929621d21e6e9946a
File hasha297eddfa7abea8d411afc0f150f8f6f30e470a77204de87e3b0815fa9bb8a84
File hash4fbd61cb9181ebbc4fe9a6e59d3c346dc00001da48d66bd890556fc6fad22b07

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago