Threat reportMalwareTL-2026-2934
ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes via Public STUN Infrastructure
ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into (TL-2026-2934), also tracked as ClingSTUN, is a high-severity malware campaign, first published 2026-10-05. It has no confirmed attribution, affects Hytec Inter HWL-2511-SS, references 16 CVEs (CVE-2022-36553, CVE-2025-34035, CVE-2024-23625), maps to 9 MITRE ATT&CK techniques (T1001.003, T1036, T1037.004), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 16Referenced vulnerabilities
- Techniques
- 9MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-2934
- Threat ID
- TL-2026-2934
- Also known as
- ClingSTUN
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- telecoms, technology, enterprise, consumer-iot, surveillance
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into
Malware and tooling: ClingSTUN
How ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into works
FortiGuard Labs reports ClingSTUN, a Linux back-connect proxy backdoor that exploits known, unpatched vulnerabilities in Internet-facing routers, IoT devices and Ivanti Connect Secure to turn them into remotely controlled proxy nodes. It uses legitimate public STUN servers for NAT traversal so its traffic resembles VoIP/WebRTC. Activity spans three campaign periods with no actor attribution.
ClingSTUN is a Linux back-connect proxy backdoor documented by FortiGuard Labs (published 2026-10-05) and tracked across three campaign periods, each with a different payload distribution host: 124.163.212.119 (period 1, about two days), 222.223.152.97 (period 2) and 118.145.196.225 (period 3, ongoing at time of reporting). The operators exploit publicly known, patchable command-injection, code-injection and authentication-bypass flaws in Internet-facing devices. Period 1 used CVE-2022-36553 (Hytec Inter HWL-2511-SS popen.cgi). Period 2 added CVE-2025-34035 (EnGenius EnShare), CVE-2024-23625 (D-Link UPnP SUBSCRIBE) and command-injection flaws in Linear, Realtek, TP-Link, AVTECH and D-Link devices. Period 3 expanded to 24 exploited vulnerabilities including Ivanti Connect Secure CVE-2023-46805 and CVE-2024-21887, MeiG Smart CVE-2026-36356 and Lantronix CVE-2025-67038, plus seven hard-coded exploits embedded in the malware for self-propagation (Realtek SDK, MVPower, TBK and KGUARD DVRs, Linksys, LB-LINK, China Mobile). The report cites more vulnerabilities than the news article; the CVE list here carries the article's IDs plus device CVEs the report names in the vendor families listed by the hunt.
Infection chain: after exploiting the device, a shell downloader (wget.sh style) moves to /tmp and fetches and runs architecture-specific ClingSTUN builds (ARM, Intel 80386, MIPS R3000, PowerPC, AMD x86-64). In the third evolution the downloader first scans /proc/mounts and, for non-proc mount points with an associated process, unmounts them and kills the process. ClingSTUN copies itself to /root/.cling or /usr/local/bin/.cling and appends itself to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot so it runs at boot. It opens /dev/watchdog or /dev/misc/watchdog and uses ioctl to disable the watchdog timer, enumerates /proc to find and kill competing malware, clears its command-line arguments so ps shows an empty command line, and copies selected /proc/1 files to /tmp and bind-mounts /tmp over its own /proc/<pid> to look like the init process.
Command and control: ClingSTUN sends STUN binding requests to hard-coded public STUN servers (24 in the second evolution, 13 in the third) to learn its external address and port mappings, and periodically sends its group identifier and mapped-port list to the same endpoints. The STUN servers are legitimate third-party infrastructure, not attacker-owned, which makes the traffic resemble VoIP/WebRTC. It listens for a 20-byte operator packet; command 1 makes it open a separate outbound TCP connection to the endpoint given in the message, receive a command and execute it, and another command triggers self-propagation. Operator motivation and attribution are not stated; the back-connect proxy function suggests building a proxy-node network from compromised devices.
MITRE ATT&CK techniques used in TL-2026-2934
Command and Control
T1001.003 Protocol or Service Impersonation; T1090 Proxy; T1095 Non-Application Layer Protocol
Defense Evasion
Persistence
Discovery
Execution
Initial Access
T1190 Exploit Public-Facing Application
Resource Development
Affected products and versions in ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into
- Hytec Inter — HWL-2511-SS
Vulnerable versions: 1.05 and earlier - EnGenius — EnShare IoT Gigabit Cloud Service (ESR/EPG devices)
Vulnerable versions: 1.4.11 and earlier - D-Link — DAP-1650, Go-RT-AC750 and other UPnP/CGI devices
Vulnerable versions: DAP-1650 1.04B01 and earlier - Ivanti — Connect Secure / Policy Secure
- Lantronix — EDS5000, G520, X300, E210, E220
Vulnerable versions: EDS5000 up to 2.1.0.0R3 - MeiG Smart — FORGE_SLT711
Vulnerable versions: MDM9607.LE.1.0-00110-STD.PROD-1 - Linear — eMerge
- Realtek — SDK-based devices
- TP-Link — Archer AX21
- AVTECH — AVM1203
Remediation for ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into
Patches
- Apply Ivanti Connect Secure / Policy Secure fixes for CVE-2023-46805 and CVE-2024-21887
- Apply vendor firmware updates for the affected EnGenius, D-Link, Linear, Realtek-SDK, TP-Link, AVTECH, Lantronix, MeiG and Hytec Inter devices where fixed firmware exists
Immediate actions
- Block 124.163.212.119, 222.223.152.97 and 118.145.196.225 at the perimeter and hunt for outbound connections to them
- Hunt Linux/IoT devices for /root/.cling, /usr/local/bin/.cling and modified /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot
- Look for devices with an empty process command line or /tmp bind-mounted over /proc/<pid>
- Alert on STUN binding traffic (UDP) originating from routers, DVRs and IoT devices that have no VoIP/WebRTC role
- Factory-reset and reflash compromised devices; rotate credentials stored on them
Workarounds
- Disable UPnP and remote management on Internet-facing devices
- Remove direct Internet exposure of device web interfaces; place behind VPN or allow-list
Longer-term hardening
- Inventory Internet-facing routers, IoT devices and VPN appliances and retire end-of-life models
- Segment IoT from corporate networks and restrict outbound UDP/STUN to approved servers
- Deploy network detection for the FortiGuard signatures BASH/Mirai.AEH!tr.dldr, BASH/Dloader.P!tr and Linux/Agent.BHT!tr
CVEs associated with ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into
CVE-2022-36553CVE-2025-34035CVE-2024-23625- CVE-2023-46805
- CVE-2024-21887
CVE-2026-36356CVE-2025-67038CVE-2024-23624CVE-2019-17621CVE-2019-7256- CVE-2021-35394
CVE-2023-1389CVE-2024-7029CVE-2024-10915CVE-2024-10914CVE-2022-37055
Weaknesses (CWE) in ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into
Timeline of ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into
- CVE-2022-36553 (Hytec Inter HWL-2511-SS popen.cgi command injection), the vulnerability used in ClingSTUN's first campaign period, is published in NVD
- CVE-2024-23625 (D-Link DAP-1650 UPnP SUBSCRIBE command injection), later used in period 2, is published in NVD
- CVE-2025-34035 (EnGenius EnShare usbinteract.cgi command injection), later used in period 2, is published in NVD
- CVE-2025-67038 (Lantronix HTTP RPC command injection, CVSS 9.8), exploited in period 3, is published in NVD
- CVE-2026-36356 (MeiG Smart FORGE_SLT711 unauthenticated command injection, CVSS 9.1), exploited in period 3, is published in NVD
- FortiGuard Labs publishes ClingSTUN analysis; period 3 (ongoing) distributes from 118.145.196.225 with 24 exploited vulnerabilities including Ivanti Connect Secure and 13 STUN servers; Infosecurity Magazine covers it the same day
- FortiGuard reports period 2: distribution from 222.223.152.97 adding EnGenius, D-Link, Linear, Realtek, TP-Link and AVTECH exploits and 24 public STUN servers (exact dates not given)
- FortiGuard reports period 1: roughly two days of ClingSTUN distribution from 124.163.212.119 exploiting CVE-2022-36553 (exact dates not given in the sources)
Sources cited for ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into
- ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure (FortiGuard Labs)
- ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes (Infosecurity Magazine)
- NVD: CVE-2022-36553 (Hytec Inter HWL-2511-SS)
- NVD: CVE-2024-23625 (D-Link DAP-1650)
- NVD: CVE-2025-34035 (EnGenius EnShare)
- NVD: CVE-2025-67038 (Lantronix)
- NVD: CVE-2026-36356 (MeiG Smart FORGE_SLT711)
Detection coverage for TL-2026-2934
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2934 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.