ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Pierluigi Paganini
October 06, 2026

Fortinet details ClingSTUN, a Linux backdoor exploiting unpatched IoT devices and abusing public STUN servers to route traffic past NAT.

FortiGuard Labs researchers spotted a Linux malware family they call ClingSTUN, and the name gives away its trick immediately. Instead of relying on a dedicated command server, the malicious code leans on STUN, the protocol that helps devices behind a router figure out their real public IP address. Video calling apps use it constantly, which means ClingSTUN’s network traffic hides inside something that already looks completely normal.

“ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes. It abuses public STUN (Session Traversal Utilities for NAT) infrastructure to discover externally mapped IP addresses and ports, maintain NAT bindings, and improve connectivity between compromised hosts and remote operators.” reads the report published by Fortinet. “Because many of the STUN servers it contacts are legitimate public services, the resulting traffic easily blends with normal VoIP and WebRTC communications.”

The attack starts with a familiar problem: old, unpatched devices exposed to the internet. Fortinet first spotted the campaign exploiting a known command injection flaw in Hytec Inter routers. As the campaign evolved, the attackers changed their download infrastructure and expanded the list of vulnerabilities they were exploiting.

In the latest wave, they were targeting devices from more than a dozen vendors, including D-Link, TP-Link, Realtek and Linksys, as well as several DVR and IoT cloud platforms. Many of these devices are easy targets because they are rarely updated or closely monitored.

Once the attackers find a vulnerable device, a small downloader script installs the right malware version for its hardware. It supports common architectures such as ARM, MIPS, PowerPC and Intel.

The latest version also checks the device for other malware before installing itself. It scans mounted filesystems and kills suspicious processes running from temporary directories. In other words, ClingSTUN is not just trying to infect the device. It also tries to remove competing malware and take full control.

The persistence mechanism is almost old-fashioned in its simplicity. The malware copies itself into two separate locations, then appends itself to three different boot scripts so it survives a reboot no matter which startup path the device actually uses. It also walks through every running process, checks whether the command line matches what the process claims to be, and kills anything that doesn’t line up, which is both a defense mechanism and a fairly blunt way of eliminating rival malware fighting for the same compromised box.

Two details stand out as genuinely well thought through rather than copy-pasted from some other botnet’s source code. First, it opens the device’s watchdog timer and quietly disables it, so the device never auto-reboots itself out of the infection the way embedded hardware is designed to if something goes wrong. Second, once it’s running as root, it swaps its own process metadata for a copy of PID 1’s, the very first process the kernel starts, which makes a basic process listing show what looks like the init system instead of malware.

“After setting up persistence, ClingSTUN clears its original command-line arguments so that its command line appears empty in tools such as “ps.” It then checks whether it is running as root (UID 0).” reads the report. “If so, it copies selected process information files from “/proc/1/” to “/tmp” and bind-mounts “/tmp” over its own “/proc/” directory, concealing its process information behind metadata copied from PID 1.”

The STUN part is especially interesting because it helps ClingSTUN hide in normal network traffic. The malware sends standard requests to public STUN servers to find out its external IP address and port. These are the same services commonly used by VoIP and WebRTC applications.

Later versions reduced the number of STUN servers and required all connections to work, which suggests the attackers were improving reliability. Because the traffic goes to legitimate third-party services, it can be difficult for defenders to tell the difference between ClingSTUN activity and normal traffic from apps such as Zoom.

Command delivery itself still needs a human on the other end willing to send a 20-byte packet the right way.

“ClingSTUN establishes a UDP socket, binds to a random local port, and sends standard 20-byte STUN binding requests. It sends these to 24 public endpoints and ensures at least half succeed.” Fortinet states. “The third evolution reduced this to 13 endpoints and ensures every endpoint connection succeeds.”

A single control datagram can trigger ClingSTUN to open a fresh outbound TCP connection to an address the operator specifies, pull down a command over that connection, and execute it, which keeps the heavy lifting off the STUN channel and limits what shows up in any one place. The malware also carries hardcoded exploits for seven more vulnerabilities purely for spreading itself further, meaning every infected device doubles as a scanner looking for its next host.

Fortinet stresses that the STUN servers are not compromised or malicious. They are simply working as intended. These third-party services should not automatically be treated as attacker-controlled infrastructure.

“ClingSTUN’s exploitation of known, unpatched vulnerabilities reinforces the importance of consistent cyber hygiene.” concludes the report. “Organizations should inventory Internet-facing devices, track their firmware and support status, and promptly apply available security updates, prioritizing vulnerabilities known to be actively exploited.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ClingSTUN)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.