Skip to content

Clingstun Linux Backdoor Abuses Public Stun Infrastructure

www.fortinet.com • October 5, 2026

How ClingSTUN combines vulnerability exploitation, persistence, and STUN-assisted connectivity on Linux devices

Affected Platforms: IoT Devices Impacted Users: Any organization Impact: Remote attackers gain control of the vulnerable systems Severity Level: High

FortiGuard Labs has been tracking a Linux malware strain we call ClingSTUN that exploits known, unpatched vulnerabilities in Internet-facing devices to establish a persistent foothold. The campaign highlights how gaps in basic cyber hygiene, including delayed patching, unsupported firmware, and unnecessarily exposed services, can leave organizations vulnerable to compromise. Maintaining an accurate device inventory, applying security updates promptly, and limiting Internet exposure are essential to reducing these opportunities.

ClingSTUN functions as a back-connect proxy backdoor, turning infected systems into remotely controlled proxy nodes. It abuses public STUN (Session Traversal Utilities for NAT) infrastructure to discover externally mapped IP addresses and ports, maintain NAT bindings, and improve connectivity between compromised hosts and remote operators. Because many of the STUN servers it contacts are legitimate public services, the resulting traffic easily blends with normal VoIP and WebRTC communications.

This article presents a technical analysis of ClingSTUN, covering its execution flow, persistence mechanisms, process-killing behavior, watchdog manipulation, STUN-based NAT traversal, and remote command execution.

We first discovered that the threat actor delivered ClingSTUN by exploiting CVE-2022-36553 from 124[.]163[.]212[.]119, a command injection vulnerability affecting Hytec Inter HWL-2511-SS routers.

We found that ClingSTUN can be split into three time periods, each with a different download source. The first download source was 124[.]163[.]212[.]119, which the threat actor accessed by exploiting devices vulnerable to CVE-2022-36553. However, this iteration lasted only two days. The download source was 222[.]223[.]152[.]97, which the threat actor began exploiting by targeting multiple vulnerabilities. The most recent download source is 118[.]145[.]196[.]225.

The attacker adjusted the initial access strategy within the second period. This time, they didn’t focus on a single vulnerability but on two: command injection in the EnGenius IoT cloud service (CVE-2025-34035) and D-Link UPnP (CVE-2024-23625).

After that, the attacker spread the malware “ClingSTUN” via several IoT command injections targeting multiple devices, including Linear, Realtek (CVE-2021-35394), TP-Link Archer AX21 (CVE-2023-1389), AVTECH AVM1203 (CVE-2024-7029), and D-Link (CVE-2024-10915). Attackers also exploited a buffer overflow vulnerability in the goform name parameter across multiple vendors' devices.

In the third period, the attacker introduced additional vulnerabilities as entry points. Below is a list of vulnerabilities current as of the date of this blog. FortiGuard Labs continues to actively collect vulnerabilities and update our signatures.

As we write this report, ClingSTUN continues to evolve, and we continue to find traces of it across different vulnerabilities.

There are three evolution downloaders. The first and second evolution downloaders have similar architectures. The downloader initially moves to “/tmp” and downloads and executes different Linux architecture versions of ClingSTUN, including ARM, Intel 80386, MIPS R3000, PowerPC, and AMD X86-64.

The third evolution downloader begins by scanning every entry in “/proc/mounts.” If an entry’s mount point has a process ID and the file system type is not “proc,” it unmounts the mount point and kills the process. , the downloader checks whether the process’s executable path is in “/tmp.” If so, it kills that process as well.

The following analysis focuses on the second evolution, “m.x86_64,” and the third evolution, “x86_64.” Both are the AMD x86-64 version of ClingSTUN.

After analyzing the malware, we found similarities to most of its botnets. They behaviors such as terminating the watchdog timer, killing competitors, setting persistence mechanisms, evading detection, and executing remote commands. They also open “/dev/watchdog” and “/dev/misc/watchdog” with read and write permissions and then terminate the watchdog timer with the system call ioctl.

ClingSTUN enumerates processes in the “/proc” directory and checks several conditions:

Determines whether the PID directory name is composed of numbers.

Skips any process that has the same process group as ClingSTUN

Reads “/proc/ /cmdline” and “/proc/ /exe” and checks the executable in “/tmp” and “/var/tmp”

Compares “/proc/ /cmdline” with the actual executable basename and kills the process if they don’t match.

The persistence mechanism focuses on three files:

ClingSTUN first copies itself into two files, “/root/.cling” and “/usr/local/bin/.cling,” and assigns executable permissions. After that, it appends the copied files to three files so the victim host executes the malware while booting.

After setting up persistence, ClingSTUN clears its original command-line arguments so that its command line appears empty in tools such as “ps.” It then checks whether it is running as root (UID 0). If so, it copies selected process information files from “/proc/1/” to “/tmp” and bind-mounts “/tmp” over its own “/proc/ ” directory, concealing its process information behind metadata copied from PID 1.

ClingSTUN establishes a UDP socket, binds to a random local port, and sends standard 20-byte STUN binding requests. It sends these to 24 public endpoints and ensures at least half succeed. The third evolution reduced this to 13 endpoints and ensures every endpoint connection succeeds.

After completing the STUN binding exchanges, ClingSTUN periodically sends its group identifier and mapped-port list to the same STUN endpoints. No separate coordination-server registration was identified in this path, and how the operator obtains the external mapping and delivers control traffic through NAT remains unverified.

However, ClingSTUN listens for a 20-byte packet from the operator that triggers additional functionality, including remote command execution and self-propagation. For remote command execution, once a control datagram reaches a retained UDP socket, command 1 triggers a separate outbound TCP connection to the endpoint specified in that message, receives a command, and executes it, as shown in Figure 11.

ClingSTUN has hard-coded exploits for seven vulnerabilities to achieve self-propagation:

ClingSTUN is a Linux back-connect proxy backdoor designed to maintain persistent access and turn compromised devices into remotely controlled proxy nodes. It combines persistence mechanisms, process termination, watchdog manipulation, and remote command execution with STUN-assisted NAT traversal. A notable feature is its abuse of legitimate public STUN servers to discover external IP addresses and port mappings, thereby helping maintain NAT connectivity. These third-party services should not be automatically classified as attacker-controlled infrastructure. Instead, defenders should assess STUN activity alongside suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic.

ClingSTUN’s exploitation of known, unpatched vulnerabilities reinforces the importance of consistent cyber hygiene. Organizations should inventory Internet-facing devices, track their firmware and support status, and promptly apply available security updates, prioritizing vulnerabilities known to be actively exploited. Replace or isolate devices that can no longer receive security updates, and disable or restrict unnecessary Internet-facing services. Combined with monitoring for suspicious processes and network activity, these practices help prevent vulnerable devices from becoming persistent backdoors and nodes in malicious proxy infrastructure.

The malware described in this report is detected and blocked by FortiGuard Antivirus as:

BASH/Mirai.AEH!tr.dldr BASH/Dloader.P!tr Linux/Agent.BHT!tr

The FortiGuard AntiVirus service engine is integrated into FortiGate , FortiMail , FortiClient , and FortiEDR . Customers running these products with up-to-date signatures are protected against the malware components described in this report.

The FortiGuard Web Filtering Service blocks the C2 server.

FortiGuard Labs provides an IPS signature against attacks exploiting the following vulnerabilities:

CVE-2026-87827: (62328) KGUARD.DVR.Unauthentication .Remote.Command.Execution CVE-2026-36356 : (61192) MeiG.Smart.FORGE_SLT711.GoAhead.web.server.OS.Command.Injection CVE-2025-67038: (61205) Lantronix.EDS5000.CVE-2025-67038.Code.Injection CVE-2025-34037: (44582) Linksys.Devices.Administrative.Console.Authentication.Bypass CVE-2025-34035: (46900) EnGenius.EnShare.IoT.Gigabit.Cloud.Service.Command.Injection CVE-2024-46048: (55059) Tenda.Devices.exeCommand.Command.Injection CVE-2024-35340: (55059) Tenda.Devices.exeCommand.Command.Injection CVE-2024-32314: (55059) Tenda.Devices.exeCommand.Command.Injection

Organizations seeking to strengthen foundational security awareness may also consider completing Fortinet Certified Fundamentals (FCF) training in Cybersecurity. This module is designed to help end users learn how to identify and protect themselves from phishing attacks.

The FortiGuard IP Reputation and Anti-Botnet Security Service proactively blocks infrastructure associated with this campaign by correlating malicious IP intelligence collected from Fortinet’s global sensor network, CERT collaborations, MITRE, trusted industry partners, and other intelligence sources.

If you believe this or any other cybersecurity threat has impacted your organization, our Global FortiGuard Incident Response Team for assistance.

124[.]163[.]212[.]119 222[.]223[.]152[.]97 118[.]145[.]196[.]225

dc892f5013edb0aa1e61e808511387373d8d120348b5be0929621d21e6e9946a a297eddfa7abea8d411afc0f150f8f6f30e470a77204de87e3b0815fa9bb8a84 4fbd61cb9181ebbc4fe9a6e59d3c346dc00001da48d66bd890556fc6fad22b07 121f2050e3c891b29565fd73451fff7ae60199c86eb8d79ec1eb1d9844578487 48f9b72ce72ab7087794650d6eef10135345088384fbde1482f1c74a02b80302 e6e113783356446aef66e5296db45b244f318292af7cebc2a9bd76f095a95c4c c1d8e2829ea63b9dc1cf2c3421a5093406adad4d6622e238376e78e908e0e6e8 48962b3893f2c8261e32e6b95ea7d463d145a529a8b2a6c987dd979454405c73 76692a23abe718b93e63edefd743971ec627c0cdf3778f856bd5ec88003deaa2 ec199c78c11040fd3127887222fd75a85e5797bf96aa691a117fdd83dd663d81 c0d8ffebfba969b1c1ca76bd9623bb623e9f95155c8ceca77d8fcc521435a497 f49f45303cbfccee14ff193ac9608f860e6d616f08c0ecbef1ec44f7c863d7ec 9391c6ad17aced1142607c0c623b18d86a7697cc483d204ffac94093e26b8068 9391c6ad17aced1142607c0c623b18d86a7697cc483d204ffac94093e26b8068 e4d12208789f36efc5a1ff765088fed95d6bb5972d1a804a4536fd42366797d4 284e5ec8748f99fd1b8c331b699a5fe5fd4448bbaae0347a940f427f931c4d14 6581bf37184bb2db899b9893064d39dd314ea691adf3281cc0aa7e0a31e5138a 10d83c1748895361e07320f68d44d427b43cadd2cbffe0ab5e607ab03aec83da 2ed54e0f988a62039abed88f6394eb1e3d5ed931f0183556055417fb08844ecf b90640b392827b4f2d280f6cf67860862953331917d42df23e1653a92f2f98ad dfba6008a2c828a9cb62342aec53006ae05a60cb8d4c41c3fa216fd727e8c6a3 5c4e263546fb21f8fe8732789a5b6583eaa8ae11ebeef099462a7c9bf50e022d

Ransomware Prevention

Product Certifications

Social Responsibility