Security researchers have detailed a new Linux botnet that breaks into routers, cameras, video recorders and virtual private network (VPN) gateways through more than 30 known flaws, and then leans on public internet calling infrastructure to keep its foothold reachable.
FortiGuard Labs researcher Vincent Li said the malware, dubbed ClingSTUN by the vendor, turns compromised devices into proxy nodes that remote operators can route traffic through.
Among the malware’s entry points are two Ivanti Connect Secure and Policy Secure flaws, CVE-2023-46805 and CVE-2024-21887, which attackers chained as zero-days from as early as December 2023.
The Australian Cyber Security Centre issued an alert on the pair of vulnerabilities for the Ivanti remote access solution in January 2024.
Nearly three years on, the bugs now sit in a commodity botnet’s toolkit, alongside flaws in Lantronix EDS5000 device servers, Linear eMerge access controllers and Sunhillo SureLine, software used by air traffic control to collect and relay radar and aircraft position data.
The bulk of the devices listed by FortiGuard cover consumer and small-business kit from D-Link, TP-Link, Tenda and others, along with digital video recorders and devices built on Realtek’s software development kit (SDK).
Most of the vulnerabilities are command injection flaws, where a device’s web interface passes attacker-supplied text straight to its operating system shell.
Once inside, a script downloads builds for ARM, MIPS, PowerPC and x86 chips and keeps whichever runs, while the latest version first kills any rival malware already squatting on the device.
ClingSTUN then switches off the device’s hardware watchdog, a safety timer that reboots the device when its software hangs, so a stall won’t knock the malware out.
It also adds itself to the scripts the device runs at start-up, ensuring it persists after restarts.
To stay out of sight, it borrows the identity of the system’s first and most trusted program, so a check of what’s running shows that program rather than the malware.
Infected machines also recruit others, carrying hard-coded exploits for seven further flaws with the oldest being a Realtek bug from 2014.
Fortinet’s Mirai detection found the downloader script for ClingSTUN and the malware has similarities with the earlier Internet of Things botnet.
It acts like a proxy for its operators rather than a denial of service traffic flooder like Mirai however.
Hiding in call traffic
ClingSTUN abuses the STUN (Session Traversal Utilities for Network Address Translation) protocol that browsers and calling apps use to discover their public internet address from behind a router.
The malware sends STUN requests to a list of public servers, 24 in one version and 13 in the next, to learn its external address and port and keeping the router’s mapping open.
Because those servers are legitimate, the traffic resembles ordinary Teams, Zoom or WebRTC activity, and Fortinet cautioned against treating them as attacker infrastructure.
An iTnews check of the listed addresses found most belong to Voice over IP telephony, internet providers and large cloud operators in Europe, North America, Singapore and South Africa with none in Australia or New Zealand.
While ClingSTUN periodically sends a group identifier and its port list to the STUN servers, Li said no separate coordination server was found for that step.
How operators obtain the mapping and deliver control traffic through to unroutable, internal networks “remains unverified”.
Fortinet recommended assessing STUN activity alongside suspicious processes, unexpected UDP connections and recurring keepalive traffic.
It also urged organisations to inventory internet-facing devices, prioritise patches for actively exploited flaws, and replace or isolate kit that no longer receives updates.

