Threat reportMalwareTL-2026-2934

ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes via Public STUN Infrastructure

highACTIVE

ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into (TL-2026-2934), also tracked as ClingSTUN, is a high-severity malware campaign, first published 2026-10-05. It has no confirmed attribution, affects Hytec Inter HWL-2511-SS, references 16 CVEs (CVE-2022-36553, CVE-2025-34035, CVE-2024-23625), maps to 9 MITRE ATT&CK techniques (T1001.003, T1036, T1037.004), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
16Referenced vulnerabilities
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-2934

Threat ID
TL-2026-2934
Also known as
ClingSTUN
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
telecoms, technology, enterprise, consumer-iot, surveillance
Target regions
Global
Detection rules
9
Indicators of compromise
28

Malware and tooling in ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into

Malware and tooling: ClingSTUN

How ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into works

FortiGuard Labs reports ClingSTUN, a Linux back-connect proxy backdoor that exploits known, unpatched vulnerabilities in Internet-facing routers, IoT devices and Ivanti Connect Secure to turn them into remotely controlled proxy nodes. It uses legitimate public STUN servers for NAT traversal so its traffic resembles VoIP/WebRTC. Activity spans three campaign periods with no actor attribution.

ClingSTUN is a Linux back-connect proxy backdoor documented by FortiGuard Labs (published 2026-10-05) and tracked across three campaign periods, each with a different payload distribution host: 124.163.212.119 (period 1, about two days), 222.223.152.97 (period 2) and 118.145.196.225 (period 3, ongoing at time of reporting). The operators exploit publicly known, patchable command-injection, code-injection and authentication-bypass flaws in Internet-facing devices. Period 1 used CVE-2022-36553 (Hytec Inter HWL-2511-SS popen.cgi). Period 2 added CVE-2025-34035 (EnGenius EnShare), CVE-2024-23625 (D-Link UPnP SUBSCRIBE) and command-injection flaws in Linear, Realtek, TP-Link, AVTECH and D-Link devices. Period 3 expanded to 24 exploited vulnerabilities including Ivanti Connect Secure CVE-2023-46805 and CVE-2024-21887, MeiG Smart CVE-2026-36356 and Lantronix CVE-2025-67038, plus seven hard-coded exploits embedded in the malware for self-propagation (Realtek SDK, MVPower, TBK and KGUARD DVRs, Linksys, LB-LINK, China Mobile). The report cites more vulnerabilities than the news article; the CVE list here carries the article's IDs plus device CVEs the report names in the vendor families listed by the hunt.

Infection chain: after exploiting the device, a shell downloader (wget.sh style) moves to /tmp and fetches and runs architecture-specific ClingSTUN builds (ARM, Intel 80386, MIPS R3000, PowerPC, AMD x86-64). In the third evolution the downloader first scans /proc/mounts and, for non-proc mount points with an associated process, unmounts them and kills the process. ClingSTUN copies itself to /root/.cling or /usr/local/bin/.cling and appends itself to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot so it runs at boot. It opens /dev/watchdog or /dev/misc/watchdog and uses ioctl to disable the watchdog timer, enumerates /proc to find and kill competing malware, clears its command-line arguments so ps shows an empty command line, and copies selected /proc/1 files to /tmp and bind-mounts /tmp over its own /proc/<pid> to look like the init process.

Command and control: ClingSTUN sends STUN binding requests to hard-coded public STUN servers (24 in the second evolution, 13 in the third) to learn its external address and port mappings, and periodically sends its group identifier and mapped-port list to the same endpoints. The STUN servers are legitimate third-party infrastructure, not attacker-owned, which makes the traffic resemble VoIP/WebRTC. It listens for a 20-byte operator packet; command 1 makes it open a separate outbound TCP connection to the endpoint given in the message, receive a command and execute it, and another command triggers self-propagation. Operator motivation and attribution are not stated; the back-connect proxy function suggests building a proxy-node network from compromised devices.

MITRE ATT&CK techniques used in TL-2026-2934

Command and Control

T1001.003 Protocol or Service Impersonation; T1090 Proxy; T1095 Non-Application Layer Protocol

Defense Evasion

T1036 Masquerading

Persistence

T1037.004 RC Scripts

Discovery

T1057 Process Discovery

Execution

T1059.004 Unix Shell

Initial Access

T1190 Exploit Public-Facing Application

Resource Development

T1584.008 Network Devices

Affected products and versions in ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into

  • Hytec Inter — HWL-2511-SS
    Vulnerable versions: 1.05 and earlier
  • EnGenius — EnShare IoT Gigabit Cloud Service (ESR/EPG devices)
    Vulnerable versions: 1.4.11 and earlier
  • D-Link — DAP-1650, Go-RT-AC750 and other UPnP/CGI devices
    Vulnerable versions: DAP-1650 1.04B01 and earlier
  • Ivanti — Connect Secure / Policy Secure
  • Lantronix — EDS5000, G520, X300, E210, E220
    Vulnerable versions: EDS5000 up to 2.1.0.0R3
  • MeiG Smart — FORGE_SLT711
    Vulnerable versions: MDM9607.LE.1.0-00110-STD.PROD-1
  • Linear — eMerge
  • Realtek — SDK-based devices
  • TP-Link — Archer AX21
  • AVTECH — AVM1203

Remediation for ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into

Patches

  • Apply Ivanti Connect Secure / Policy Secure fixes for CVE-2023-46805 and CVE-2024-21887
  • Apply vendor firmware updates for the affected EnGenius, D-Link, Linear, Realtek-SDK, TP-Link, AVTECH, Lantronix, MeiG and Hytec Inter devices where fixed firmware exists

Immediate actions

  • Block 124.163.212.119, 222.223.152.97 and 118.145.196.225 at the perimeter and hunt for outbound connections to them
  • Hunt Linux/IoT devices for /root/.cling, /usr/local/bin/.cling and modified /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot
  • Look for devices with an empty process command line or /tmp bind-mounted over /proc/<pid>
  • Alert on STUN binding traffic (UDP) originating from routers, DVRs and IoT devices that have no VoIP/WebRTC role
  • Factory-reset and reflash compromised devices; rotate credentials stored on them

Workarounds

  • Disable UPnP and remote management on Internet-facing devices
  • Remove direct Internet exposure of device web interfaces; place behind VPN or allow-list

Longer-term hardening

  • Inventory Internet-facing routers, IoT devices and VPN appliances and retire end-of-life models
  • Segment IoT from corporate networks and restrict outbound UDP/STUN to approved servers
  • Deploy network detection for the FortiGuard signatures BASH/Mirai.AEH!tr.dldr, BASH/Dloader.P!tr and Linux/Agent.BHT!tr

CVEs associated with ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into

  • CVE-2022-36553
  • CVE-2025-34035
  • CVE-2024-23625
  • CVE-2023-46805
  • CVE-2024-21887
  • CVE-2026-36356
  • CVE-2025-67038
  • CVE-2024-23624
  • CVE-2019-17621
  • CVE-2019-7256
  • CVE-2021-35394
  • CVE-2023-1389
  • CVE-2024-7029
  • CVE-2024-10915
  • CVE-2024-10914
  • CVE-2022-37055

Weaknesses (CWE) in ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into

CWE-77, CWE-78, CWE-306

Timeline of ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into

  • CVE-2022-36553 (Hytec Inter HWL-2511-SS popen.cgi command injection), the vulnerability used in ClingSTUN's first campaign period, is published in NVD
  • CVE-2024-23625 (D-Link DAP-1650 UPnP SUBSCRIBE command injection), later used in period 2, is published in NVD
  • CVE-2025-34035 (EnGenius EnShare usbinteract.cgi command injection), later used in period 2, is published in NVD
  • CVE-2025-67038 (Lantronix HTTP RPC command injection, CVSS 9.8), exploited in period 3, is published in NVD
  • CVE-2026-36356 (MeiG Smart FORGE_SLT711 unauthenticated command injection, CVSS 9.1), exploited in period 3, is published in NVD
  • FortiGuard Labs publishes ClingSTUN analysis; period 3 (ongoing) distributes from 118.145.196.225 with 24 exploited vulnerabilities including Ivanti Connect Secure and 13 STUN servers; Infosecurity Magazine covers it the same day
  • FortiGuard reports period 2: distribution from 222.223.152.97 adding EnGenius, D-Link, Linear, Realtek, TP-Link and AVTECH exploits and 24 public STUN servers (exact dates not given)
  • FortiGuard reports period 1: roughly two days of ClingSTUN distribution from 124.163.212.119 exploiting CVE-2022-36553 (exact dates not given in the sources)

Sources cited for ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into

Detection coverage for TL-2026-2934

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2934 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats