Skip to content
ClingSTUN Linux Backdoor Exploits 24 IoT Vulnerabilities

ClingSTUN Linux Backdoor Exploits 24 IoT Vulnerabilities

First seen 5 Oct 2026, 14:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 12:58 UTC
  • •ClingSTUN exploits 24 known vulnerabilities in IoT devices, turning them into proxy nodes.
  • •The malware uses legitimate STUN servers to obscure its communications, complicating detection.
  • •FortiGuard Labs has not identified the attackers or the extent of the infections.

Researchers from FortiGuard Labs have identified a new Linux backdoor named ClingSTUN that exploits 24 known vulnerabilities in Internet of Things (IoT) devices. This malware turns infected devices into proxy nodes, using legitimate public STUN servers to obscure communications. The vulnerabilities targeted include critical flaws from manufacturers like D-Link, Realtek, and TP-Link. ClingSTUN establishes persistence on compromised systems and can propagate itself using hardcoded exploits for seven additional vulnerabilities. The malware has been observed in multiple attack waves, with its operators expanding the list of exploited vulnerabilities over time. FortiGuard Labs has not confirmed the identity of the attackers or the number of affected devices. The use of legitimate STUN servers complicates detection, as the traffic resembles normal Internet communications. Organizations are urged to inventory their IoT devices and prioritize patching to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2015-05-01
CVE-2014-8361 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-08-13
CVE-2021-36380 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-08-29
CVE-2022-36553 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-10
CVE-2024-21887 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2024-01-10
CVE-2023-46805 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2024-01-25
CVE-2024-23625 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-06-24
CVE-2025-34035 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-11
CVE-2025-67038 published
A critical vulnerability in IoT devices was disclosed, later added to CISA's KEV list.
Hackread
2026-05-05
CVE-2026-36356 published
A critical command injection vulnerability affecting MeiG Smart devices was disclosed.
Darkreading
2026-09-09
CVE-2026-87827 published
A critical remote code execution vulnerability was disclosed, further expanding the attack surface.
Infosecurity-Magazine

More articles in this cluster (13)

Following this threat?

Track ClingSTUN, Realtek and CVE-2022-36553 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which devices are affected by ClingSTUN?
ClingSTUN targets a wide range of IoT devices from manufacturers like D-Link, Realtek, and TP-Link.
What should organizations do to protect against ClingSTUN?
Organizations should inventory their IoT devices, prioritize patching known vulnerabilities, and monitor STUN traffic for suspicious activity.
Is there a known method for detecting ClingSTUN infections?
Detection can be challenging due to the use of legitimate STUN servers, but monitoring for unusual UDP connections and process behavior is recommended.