# ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes via Public STUN Infrastructure

> FortiGuard Labs reports ClingSTUN, a Linux back-connect proxy backdoor that exploits known, unpatched vulnerabilities in Internet-facing routers, IoT devices and Ivanti Connect Secure to turn them into remotely controlled proxy nodes. It uses legitimate public STUN servers for NAT traversal so its traffic resembles VoIP/WebRTC. Activity spans three campaign periods with no actor attribution.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2934
- **ID:** TL-2026-2934
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2022-36553, CVE-2025-34035, CVE-2024-23625, CVE-2023-46805, CVE-2024-21887, CVE-2026-36356, CVE-2025-67038, CVE-2024-23624, CVE-2019-17621, CVE-2019-7256, CVE-2021-35394, CVE-2023-1389, CVE-2024-7029, CVE-2024-10915, CVE-2024-10914, CVE-2022-37055

## Description

ClingSTUN is a Linux back-connect proxy backdoor documented by FortiGuard Labs (published 2026-10-05) and tracked across three campaign periods, each with a different payload distribution host: 124.163.212.119 (period 1, about two days), 222.223.152.97 (period 2) and 118.145.196.225 (period 3, ongoing at time of reporting). The operators exploit publicly known, patchable command-injection, code-injection and authentication-bypass flaws in Internet-facing devices. Period 1 used CVE-2022-36553 (Hytec Inter HWL-2511-SS popen.cgi). Period 2 added CVE-2025-34035 (EnGenius EnShare), CVE-2024-23625 (D-Link UPnP SUBSCRIBE) and command-injection flaws in Linear, Realtek, TP-Link, AVTECH and D-Link devices. Period 3 expanded to 24 exploited vulnerabilities including Ivanti Connect Secure CVE-2023-46805 and CVE-2024-21887, MeiG Smart CVE-2026-36356 and Lantronix CVE-2025-67038, plus seven hard-coded exploits embedded in the malware for self-propagation (Realtek SDK, MVPower, TBK and KGUARD DVRs, Linksys, LB-LINK, China Mobile). The report cites more vulnerabilities than the news article; the CVE list here carries the article's IDs plus device CVEs the report names in the vendor families listed by the hunt.

Infection chain: after exploiting the device, a shell downloader (wget.sh style) moves to /tmp and fetches and runs architecture-specific ClingSTUN builds (ARM, Intel 80386, MIPS R3000, PowerPC, AMD x86-64). In the third evolution the downloader first scans /proc/mounts and, for non-proc mount points with an associated process, unmounts them and kills the process. ClingSTUN copies itself to /root/.cling or /usr/local/bin/.cling and appends itself to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot so it runs at boot. It opens /dev/watchdog or /dev/misc/watchdog and uses ioctl to disable the watchdog timer, enumerates /proc to find and kill competing malware, clears its command-line arguments so ps shows an empty command line, and copies selected /proc/1 files to /tmp and bind-mounts /tmp over its own /proc/<pid> to look like the init process.

Command and control: ClingSTUN sends STUN binding requests to hard-coded public STUN servers (24 in the second evolution, 13 in the third) to learn its external address and port mappings, and periodically sends its group identifier and mapped-port list to the same endpoints. The STUN servers are legitimate third-party infrastructure, not attacker-owned, which makes the traffic resemble VoIP/WebRTC. It listens for a 20-byte operator packet; command 1 makes it open a separate outbound TCP connection to the endpoint given in the message, receive a command and execute it, and another command triggers self-propagation. Operator motivation and attribution are not stated; the back-connect proxy function suggests building a proxy-node network from compromised devices.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059.004 Unix Shell
- T1037.004 RC Scripts
- T1036 Masquerading
- T1057 Process Discovery
- T1090 Proxy
- T1095 Non-Application Layer Protocol
- T1001.003 Protocol or Service Impersonation
- T1584.008 Network Devices

## Sources

- [ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure (FortiGuard Labs)](https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure)
- [ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes (Infosecurity Magazine)](https://www.infosecurity-magazine.com/news/clingstun-backdoor-unpatched-iot/)
- [NVD: CVE-2022-36553 (Hytec Inter HWL-2511-SS)](https://nvd.nist.gov/vuln/detail/CVE-2022-36553)
- [NVD: CVE-2024-23625 (D-Link DAP-1650)](https://nvd.nist.gov/vuln/detail/CVE-2024-23625)
- [NVD: CVE-2025-34035 (EnGenius EnShare)](https://nvd.nist.gov/vuln/detail/CVE-2025-34035)
- [NVD: CVE-2025-67038 (Lantronix)](https://nvd.nist.gov/vuln/detail/CVE-2025-67038)
- [NVD: CVE-2026-36356 (MeiG Smart FORGE_SLT711)](https://nvd.nist.gov/vuln/detail/CVE-2026-36356)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2934
