<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/clingstun-malware-turns-vulnerable-iot-devices-into-proxy-nodes-using-public-stun-servers-pbwtz2k8c" -->

---
title: ClingSTUN malware turns vulnerable IoT devices into...
description: FortiGuard Labs has identified ClingSTUN, a Linux back-connect proxy backdoor that compromises Internet-facing IoT devices by exploiting at least 24 known,...
canonical: https://daily.dev/posts/clingstun-malware-turns-vulnerable-iot-devices-into-proxy-nodes-using-public-stun-servers-pbwtz2k8c
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: ClingSTUN malware turns vulnerable IoT devices into proxy nodes using public STUN servers | daily.dev
og:description: FortiGuard Labs has identified ClingSTUN, a Linux back-connect proxy backdoor that compromises Internet-facing IoT devices by exploiting at least 24 known,...
og:url: https://daily.dev/posts/clingstun-malware-turns-vulnerable-iot-devices-into-proxy-nodes-using-public-stun-servers-pbwtz2k8c
og:image: https://api.daily.dev/og/posts/PbwtZ2k8c.png
og:image:alt: ClingSTUN malware turns vulnerable IoT devices into proxy nodes using public STUN servers
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# ClingSTUN malware turns vulnerable IoT devices into proxy nodes using public STUN servers

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

FortiGuard Labs has identified ClingSTUN, a Linux back-connect proxy backdoor that compromises Internet-facing IoT devices by exploiting at least 24 known, unpatched vulnerabilities in products from D-Link, Realtek, Ivanti, TP-Link and Tenda. It abuses public STUN servers, normally used for VoIP/WebRTC NAT traversal, to disguise its command-and-control traffic as ordinary voice and video traffic. Once active, it kills rival processes, disables the hardware watchdog, hides behind PID 1 process metadata, and persists through boot scripts. The malware has evolved through three generations of downloaders and carries seven additional hard-coded exploits to spread further, turning infected devices into proxy nodes that let attackers route traffic through an enterprise's public IP. Fortinet recommends inventorying devices, patching firmware promptly, segmenting networks, and monitoring outbound traffic for unusual STUN activity, and has published IOCs and affected CVEs.

## Content

FortiGuard Labs has documented a new Linux backdoor called ClingSTUN. It breaks into vulnerable Internet-facing IoT devices and turns them into back-connect proxy nodes, which attackers can use to route traffic through an organization's public IP address.

## Targets and entry

ClingSTUN gets in through known, unpatched flaws: command injection, code injection and buffer overflows. FortiGuard counts at least 24 vulnerabilities across devices from D-Link, Realtek, Ivanti, TP-Link, Hytec, EnGenius, AVTECH and Tenda. The affected hardware includes routers, DVRs, cameras, UPnP stacks and Ivanti Connect Secure. The malware has builds for ARM, Intel 80386, MIPS, PowerPC and x86-64, so it runs on most embedded hardware.

Once on a device, it spreads using seven additional hard-coded exploits aimed at other vulnerable devices. FortiGuard has also tracked it through three generations of downloaders.

## The STUN trick

The unusual part is how ClingSTUN hides its command infrastructure. STUN servers are public services built for VoIP and WebRTC. They help a device behind NAT learn its external IP address and port mapping. ClingSTUN uses them for that same purpose, so its traffic looks like ordinary call-setup activity.

This makes blocklists a weak defense. The destinations are legitimate and widely used, so there is little reputation signal to match against.

## Staying on the device

On the host, the malware:

- kills competing processes
- disables the hardware watchdog timer, so the device won't reboot itself out of trouble
- hides by copying the process metadata of PID 1 (init)
- persists through startup scripts that run at boot

## What defenders can do

The advice is mostly basic hygiene, which is the point: these devices are compromised through old, known bugs.

- Keep an accurate inventory of IoT and edge devices, including firmware versions.
- Patch promptly, and retire hardware that no longer gets updates.
- Segment these devices from the rest of the network.
- Monitor outbound traffic for unexpected STUN activity, and watch device behavior rather than trusting destination reputation.

Fortinet has published indicators of compromise and the full list of affected CVEs.

## Questions this post answers

### What is ClingSTUN malware and how does it use STUN servers to hide its command and control traffic?

ClingSTUN is a Linux back-connect proxy backdoor documented by FortiGuard Labs that infects Internet-facing IoT devices by exploiting at least 24 unpatched vulnerabilities in gear from D-Link, Realtek, Ivanti, TP-Link, and Tenda. It queries public STUN servers, normally used for VoIP and WebRTC NAT traversal, to learn its external IP and port mapping, letting its C2 traffic blend in with ordinary voice and video traffic.

_Teams hardening IoT fleets against novel C2 evasion techniques can follow emerging malware research on daily.dev._

### Which vendors and device types are affected by the ClingSTUN IoT malware?

Affected hardware includes routers, DVRs, UPnP stacks, and Ivanti Connect Secure, with vulnerable products from D-Link, Realtek, Ivanti, TP-Link, and Tenda. The malware exploits at least 24 known, unpatched flaws to gain initial access and carries seven additional hard-coded exploits to spread further across vulnerable devices on the network.

_Anyone auditing exposed routers and VPN gateways for known CVEs can track disclosures like this on daily.dev._

### How can organizations detect or mitigate IoT devices compromised into proxy nodes by malware like ClingSTUN?

Fortinet recommends keeping an accurate device inventory, applying firmware updates promptly, segmenting the network, and monitoring outbound traffic for unusual STUN activity, since compromised devices become proxy nodes that let attackers route traffic through an enterprise's public IP address. Fortinet has published indicators of compromise and the full list of affected CVEs.

_Network defenders building outbound-traffic monitoring rules can follow practical IoT mitigation guidance on daily.dev._

## Similar posts on daily.dev

- [AryStinger botnet infected thousands of D-Link routers worldwide](https://daily.dev/posts/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide-9f0wocue1) · BleepingComputer · 0 upvotes · 0 comments
- [Chinese Cyber Threat Lurks In Critical Asian Sectors for Years](https://daily.dev/posts/chinese-cyber-threat-lurks-in-critical-asian-sectors-for-years-8fwvgxfsv) · Dark Reading · 0 upvotes · 0 comments
- [SSHStalker botnet brute-forces its way onto 7,000 Linux machines](https://daily.dev/posts/sshstalker-botnet-brute-forces-its-way-onto-7-000-linux-machines-d1nrvsgyf) · CSO Online · 14 upvotes · 0 comments
- [China-linked crews turn routers into covert attack proxies](https://daily.dev/posts/china-linked-crews-turn-routers-into-covert-attack-proxies-dfktw66a9) · The Register · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/clingstun-malware-turns-vulnerable-iot-devices-into-proxy-nodes-using-public-stun-servers-pbwtz2k8c)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"ClingSTUN malware turns vulnerable IoT devices into proxy nodes using public STUN servers","url":"https://daily.dev/posts/clingstun-malware-turns-vulnerable-iot-devices-into-proxy-nodes-using-public-stun-servers-pbwtz2k8c","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/clingstun-malware-turns-vulnerable-iot-devices-into-proxy-nodes-using-public-stun-servers-pbwtz2k8c"},"datePublished":"2026-10-05T21:55:23.311Z","dateModified":"2026-10-06T12:12:53.875Z","description":"FortiGuard Labs has identified ClingSTUN, a Linux back-connect proxy backdoor that compromises Internet-facing IoT devices by exploiting at least 24 known,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2ff66bf5ec721aecdbafe321bf042eef?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2ff66bf5ec721aecdbafe321bf042eef?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/clingstun-malware-turns-vulnerable-iot-devices-into-proxy-nodes-using-public-stun-servers-pbwtz2k8c","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,malware","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"ClingSTUN malware turns vulnerable IoT devices into proxy nodes using public STUN servers"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/clingstun-malware-turns-vulnerable-iot-devices-into-proxy-nodes-using-public-stun-servers-pbwtz2k8c#faq","mainEntity":[{"@type":"Question","name":"What is ClingSTUN malware and how does it use STUN servers to hide its command and control traffic?","acceptedAnswer":{"@type":"Answer","text":"ClingSTUN is a Linux back-connect proxy backdoor documented by FortiGuard Labs that infects Internet-facing IoT devices by exploiting at least 24 unpatched vulnerabilities in gear from D-Link, Realtek, Ivanti, TP-Link, and Tenda. It queries public STUN servers, normally used for VoIP and WebRTC NAT traversal, to learn its external IP and port mapping, letting its C2 traffic blend in with ordinary voice and video traffic. Teams hardening IoT fleets against novel C2 evasion techniques can follow emerging malware research on daily.dev."}},{"@type":"Question","name":"Which vendors and device types are affected by the ClingSTUN IoT malware?","acceptedAnswer":{"@type":"Answer","text":"Affected hardware includes routers, DVRs, UPnP stacks, and Ivanti Connect Secure, with vulnerable products from D-Link, Realtek, Ivanti, TP-Link, and Tenda. The malware exploits at least 24 known, unpatched flaws to gain initial access and carries seven additional hard-coded exploits to spread further across vulnerable devices on the network. Anyone auditing exposed routers and VPN gateways for known CVEs can track disclosures like this on daily.dev."}},{"@type":"Question","name":"How can organizations detect or mitigate IoT devices compromised into proxy nodes by malware like ClingSTUN?","acceptedAnswer":{"@type":"Answer","text":"Fortinet recommends keeping an accurate device inventory, applying firmware updates promptly, segmenting the network, and monitoring outbound traffic for unusual STUN activity, since compromised devices become proxy nodes that let attackers route traffic through an enterprise's public IP address. Fortinet has published indicators of compromise and the full list of affected CVEs. Network defenders building outbound-traffic monitoring rules can follow practical IoT mitigation guidance on daily.dev."}}]}
```

