ClingSTUN is a Linux back-connect proxy backdoor that converts compromised Internet-facing routers, cameras, digital video recorders, and other connected equipment into persistent, remotely controlled proxy nodes. It enables attackers to relay traffic through infected devices, execute commands, and scan for additional vulnerable systems. Identified by Fortinet’s FortiGuard Labs in October 2026, it supports ARM, MIPS, PowerPC, 32-bit x86, and x86-64 architectures.
ClingSTUN is deployed through exploitation of approximately two dozen known vulnerabilities across multiple vendors’ products. Initial-access exploits include CVE-2022-36553 in Hytec Inter routers, CVE-2025-34035 in EnGenius products, CVE-2024-23625 in D-Link UPnP services, and CVE-2023-1389 in TP-Link routers. Architecture-specific downloaders retrieve and execute compatible payloads. The backdoor also contains seven hardcoded vulnerability exploits for self-propagation to additional routers and recording equipment. Its operators have not been publicly identified, and no confirmed victim organizations or infection counts have been disclosed.
The malware establishes boot-time persistence by creating hidden executable copies and modifying system initialization scripts. It terminates competing processes, disables watchdog timers, and clears its command-line arguments. When running with root privileges, it conceals its process metadata using information copied from the system’s initial process.
ClingSTUN abuses legitimate public Session Traversal Utilities for NAT (STUN) services to discover external address and port mappings and maintain NAT bindings. This activity can resemble ordinary VoIP and WebRTC traffic; the public STUN services are not established as compromised or attacker-controlled. Operator control packets can trigger self-propagation or an outbound TCP connection through which commands are retrieved and executed. The complete mechanism by which operators obtain mappings and deliver control traffic through NAT remains unverified.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The campaign exploited multiple vulnerabilities, including CVE-2022-36553, CVE-2025-34035, CVE-2024-23625, CVE-2021-35394, and CVE-2023-1389, across devices from several vendors. | ClingSTUN is a Linux backdoor that exploits unpatched vulnerabilities in Internet-facing routers and IoT devices to establish persistent access and turn compromised systems into remotely controlled proxy nodes.
The campaign exploited multiple vulnerabilities, including CVE-2022-36553, CVE-2025-34035, CVE-2024-23625, CVE-2021-35394, and CVE-2023-1389, across devices from several vendors. | ClingSTUN is a Linux backdoor that exploits unpatched vulnerabilities in Internet-facing routers and IoT devices to establish persistent access and turn compromised systems into remotely controlled proxy nodes.
The campaign exploited multiple vulnerabilities, including CVE-2022-36553, CVE-2025-34035, CVE-2024-23625, CVE-2021-35394, and CVE-2023-1389, across devices from several vendors. | ClingSTUN is a Linux backdoor that exploits unpatched vulnerabilities in Internet-facing routers and IoT devices to establish persistent access and turn compromised systems into remotely controlled proxy nodes.
The campaign exploited multiple vulnerabilities, including CVE-2022-36553, CVE-2025-34035, CVE-2024-23625, CVE-2021-35394, and CVE-2023-1389, across devices from several vendors. | ClingSTUN is a Linux backdoor that exploits unpatched vulnerabilities in Internet-facing routers and IoT devices to establish persistent access and turn compromised systems into remotely controlled proxy nodes.
The campaign exploited multiple vulnerabilities, including CVE-2022-36553, CVE-2025-34035, CVE-2024-23625, CVE-2021-35394, and CVE-2023-1389, across devices from several vendors. | ClingSTUN is a Linux backdoor that exploits unpatched vulnerabilities in Internet-facing routers and IoT devices to establish persistent access and turn compromised systems into remotely controlled proxy nodes.
The campaign also exploited CVE-2024-7029 in AVTECH AVM1203 cameras, a weakness previously associated with Mirai attacks against cameras in another campaign. | ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote access. Rather than simply infecting routers and cameras, it turns compromised equipment into remotely controlled proxy nodes that can relay traffic and run commands.
The oldest of the set is a long-patched command injection vulnerability from 2021 (CVE-2021-36380) in Sunhillo SureLine surveillance data distribution software used by the FAA and other aviation authorities. | Fortinet’s FortiGuard Labs researchers identified the malware, which they have dubbed "ClingSTUN," after tracking attacks targeting at least 24 known vulnerabilities in IoT devices.
The malware also includes hard-coded exploits for seven additional vulnerabilities that it can use to spread from an infected device to other vulnerable IoT systems. ... The oldest of these vulnerabilities is CVE-2014-8361 from 2014 in a Realtek device. | Fortinet’s FortiGuard Labs researchers identified the malware, which they have dubbed "ClingSTUN," after tracking attacks targeting at least 24 known vulnerabilities in IoT devices.
The most recent is CVE-2026-87827, a remote code execution vulnerability in KGUARD DVR from earlier this year. | Fortinet’s FortiGuard Labs researchers identified the malware, which they have dubbed "ClingSTUN," after tracking attacks targeting at least 24 known vulnerabilities in IoT devices.
The most recent is a command injection flaw from earlier this year (CVE-2026-36356) that affects MeiG Smart FORGE_SLT711 devices. | Fortinet’s FortiGuard Labs researchers identified the malware, which they have dubbed "ClingSTUN," after tracking attacks targeting at least 24 known vulnerabilities in IoT devices.
CVE-2024-32314 is included in the campaign's Tenda exeCommand command injection group. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
The campaign vulnerability table includes CVE-2022-26289 in its Tenda exeCommand command injection group. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
The campaign table lists CVE-2024-21887 affecting Ivanti Connect Secure and Policy Secure through command injection. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
CVE-2024-35340 is grouped with Tenda exeCommand command injection vulnerabilities in the campaign table. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
The hard-coded self-propagation exploit table lists CVE-2016-20016 affecting MVPower CCTV DVR. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
CVE-2023-46805 is listed as an authentication bypass affecting Ivanti Connect Secure and Policy Secure. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
The campaign table identifies CVE-2024-46048 as Tenda exeCommand command injection. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
The self-propagation table lists CVE-2025-34037, Linksys, and the ttcp_ip entry point. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
The initial-access table lists CVE-2022-37055, D-Link Go-RT-AC750, hnap_main, and buffer overflow. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
CVE-2022-35555 is listed among the Tenda exeCommand command injection entry points. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
ClingSTUN's hard-coded self-propagation exploits include CVE-2024-3721 affecting TBK DVR. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
The campaign vulnerability table lists CVE-2019-7256, Linear eMerge, card_scan_decoder.php, and command injection. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
The campaign lists CVE-2024-32292 among Tenda exeCommand command injection vulnerabilities. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
CVE-2024-23624 is listed among the campaign's vulnerabilities and associated with D-Link UPnP SUBSCRIBE CGI remote code injection. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
ClingSTUN's self-propagation table lists CVE-2023-26801 affecting LB-LINK through the mac entry point. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
The attacker spread ClingSTUN through command injections targeting D-Link (CVE-2024-10915). | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
CVE-2024-10914 is grouped with D-Link account_mgr.cgi command injection in the initial-access table. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
The hard-coded self-propagation exploit table lists CVE-2023-41011 affecting China Mobile HG6543C4. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
CVE-2019-17621 appears in the campaign vulnerability table and is associated with D-Link UPnP SUBSCRIBE CGI remote code injection. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
The campaign vulnerability table lists CVE-2025-67038 affecting Lantronix EDS5000 through code injection. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
CVE-2024-32281 appears in the campaign's Tenda exeCommand command injection group. | “ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes.”
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux backdoor deployed through exploitation of vulnerable Internet-facing routers and IoT devices. It provides persistent access, remote command execution, and proxying through compromised systems. It abuses legitimate public STUN infrastructure for NAT traversal and connectivity, helping malicious traffic blend with normal VoIP/WebRTC communications.
Compromises Linux-based routers, cameras, and other connected devices through known vulnerabilities, turning them into remotely controlled proxy nodes. Supports remote command execution and self-propagation using seven built-in exploits. Establishes boot persistence through hidden executable copies and startup-file modifications, conceals process information, disables watchdog timers, and terminates competing processes. Uses public STUN services to discover external address and port mappings; researchers could not verify how operators obtain those mappings and deliver control traffic through NAT. The report identifies three campaign stages but provides no confirmed victim list or infection count.
A Linux backdoor targeting internet-facing routers, cameras, and recording equipment through known vulnerabilities. It supports multiple processor architectures, remote command execution, traffic relaying, and self-propagation through seven built-in exploits. It persists through hidden executable copies and modifications to startup files, conceals process information, disables watchdog timers, and terminates competing processes. Public STUN services provide external address and port mappings; these services are not confirmed attacker-controlled infrastructure. Researchers identified three campaign stages but did not establish infection counts, confirmed victims, operator attribution, or how operators deliver control traffic through NAT.
Linux backdoor targeting internet-exposed routers, DVRs, and other IoT devices through known, unpatched vulnerabilities. Architecture-specific downloader scripts deploy versions supporting ARM, MIPS, PowerPC, and Intel hardware. It abuses legitimate public STUN services for NAT traversal, blending with normal VoIP and WebRTC traffic; these services are not described as compromised or attacker-controlled. An operator-supplied control datagram triggers an outbound TCP connection through which the malware retrieves and executes commands. It persists through multiple copies and boot-script modifications, terminates competing malware, disables the device watchdog timer, clears command-line arguments, and, when running as root, conceals process information using metadata copied from PID 1. Hardcoded exploits for seven additional vulnerabilities enable infected devices to scan for and compromise further hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.