Skip to content
ClingSTUN Linux Backdoor Exploits STUN Protocol and Multiple Vulnerabilities

ClingSTUN Linux Backdoor Exploits STUN Protocol and Multiple Vulnerabilities

First seen 5 Oct 2026, 14:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 14:26 UTC
  • •ClingSTUN exploits over 24 vulnerabilities in IoT devices for remote access.
  • •It uses the STUN protocol to maintain connectivity and evade detection.
  • •Organizations are advised to enhance their cybersecurity practices to prevent infections.

The ClingSTUN backdoor has been identified as a Linux malware that exploits numerous vulnerabilities in Internet-facing devices, turning them into proxy nodes for remote attackers. It targets flaws in devices from manufacturers like D-Link, TP-Link, and Realtek, utilizing the STUN protocol for NAT traversal to maintain connectivity. The malware exploits at least 24 vulnerabilities for initial access and includes a self-propagation mechanism with hardcoded exploits for additional vulnerabilities. ClingSTUN establishes persistence by copying itself to hidden files and modifying system initialization scripts. The malware's traffic blends with legitimate STUN server communications, complicating detection efforts. Organizations are urged to improve their cybersecurity hygiene by applying security updates and limiting Internet exposure to mitigate risks. FortiGuard Labs has been monitoring this threat closely, emphasizing the importance of maintaining an accurate device inventory.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-05
ClingSTUN malware reported
FortiGuard Labs disclosed the ClingSTUN backdoor, detailing its exploitation of multiple vulnerabilities and STUN protocol abuse.
Fortinet
2026-10-05
Securityweek coverage published
Securityweek published an article on ClingSTUN, highlighting its self-propagation and persistence mechanisms.
Securityweek

More articles in this cluster (2)

Following this threat?

Track ClingSTUN, Realtek and CVE-2021-35394 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What devices are affected by ClingSTUN?
ClingSTUN targets Internet-facing devices from manufacturers like D-Link, TP-Link, and Realtek.
How does ClingSTUN maintain connectivity?
It abuses public STUN servers to discover external IP addresses and maintain NAT bindings.
What actions should organizations take?
Organizations should apply security updates promptly and limit Internet exposure to vulnerable devices.