GBHackers

ClingSTUN Malware Turns Vulnerable IoT Devices Into Persistent Remote Proxy Nodes


ClingSTUN, a Linux backdoor that exploits unpatched internet-facing devices and converts them into persistent, remotely controlled proxy nodes.

The malware combines startup persistence, process concealment, competitor termination, and remote command execution with legitimate STUN infrastructure to support connectivity through network address translation.

The research published October 5 documents three campaign periods with changing payload servers and expanding exploitation capabilities.

Its defining feature is not a new vulnerability, but the integration of established exploitation techniques with public NAT-traversal services, allowing malicious communications to resemble ordinary VoIP and WebRTC traffic.

That distribution phase lasted two days before the attacker switched to 222[.]223[.]152[.]97. The latest observed download source was 118[.]145[.]196[.]225.

Subsequent activity targeted EnGenius cloud services through CVE-2025-34035 and D-Link UPnP through CVE-2024-23625, before broadening to Realtek SDK, TP-Link Archer AX21, AVTECH cameras, Linear access-control systems, and additional devices.


Initial access packet via EnGenius command injection (CVE-2025-34035)(Source : FortiGuard).
Initial access packet via EnGenius command injection (CVE-2025-34035)(Source : FortiGuard).

FortiGuard said in a report shared with GBhackers, the initial campaign delivered ClingSTUN from 124[.]163[.]212[.]119 through CVE-2022-36553, a command injection vulnerability affecting Hytec Inter HWL-2511-SS routers.

The expanding exploit set also included Ivanti appliances and Tenda equipment.

ClingSTUN Malware

One targeted vulnerability, CVE-2023-1389, enables unauthenticated command injection on vulnerable TP-Link Archer AX21 firmware.

CISA added it to its Known Exploited Vulnerabilities catalog on May 1, 2023, underscoring how previously documented weaknesses remain useful entry points for evolving malware campaigns.

Early downloaders execute architecture-specific payloads supporting ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64.

The third downloader adds aggressive cleanup, inspecting mounted paths and terminating processes associated with suspicious mounts or executables under /tmp.

 Terminating the watchdog timer (Source : FortiGuard).

ClingSTUN disables watchdog timers through ioctl operations against /dev/watchdog and /dev/misc/watchdog.

It also enumerates /proc, examines executable paths and command lines, and kills selected processes, including potential competitors operating from temporary directories.

For persistence, the backdoor copies itself to /root/.cling and /usr/local/bin/.cling, assigns executable permissions, and modifies /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot to launch during startup.

The malware then clears its original command-line arguments.

When running as root, it copies selected metadata from /proc/1/ into /tmp and bind-mounts that directory over its own process entry, obscuring process information behind data associated with the init process.

STUN binding with public endpoint (Source : FortiGuard).
 STUN binding with public endpoint (Source : FortiGuard).

ClingSTUN binds a UDP socket to a random local port and sends standard 20-byte STUN binding requests.

The second evolution contacts 24 public endpoints and requires at least half to succeed; the third reduces the set to 13 and requires every endpoint connection to succeed.

Afterward, it periodically transmits its group identifier and mapped-port list to those endpoints.

Researchers did not identify separate coordination-server registration in this path, and how operators obtain mappings and deliver control traffic through NAT remains unverified.

A 20-byte operator packet activates additional functionality. Command 1 initiates an outbound TCP connection to a supplied endpoint, retrieves a command, and executes it. Seven embedded exploits additionally support self-propagation.

Defenders should correlate unexpected STUN traffic with recurring UDP keepalives, startup-file changes, hidden .cling binaries, and unusual process mounts.

Legitimate public STUN servers are not inherently attacker-controlled indicators. Accurate inventories, timely firmware updates, and reduced internet exposure directly address the campaign’s enabling conditions.

IOCs

TypeIndicator
Host124[.]163[.]212[.]119
Host222[.]223[.]152[.]97
Host118[.]145[.]196[.]225
File hashdc892f5013edb0aa1e61e808511387373d8d120348b5be0929621d21e6e9946a
File hasha297eddfa7abea8d411afc0f150f8f6f30e470a77204de87e3b0815fa9bb8a84
File hash4fbd61cb9181ebbc4fe9a6e59d3c346dc00001da48d66bd890556fc6fad22b07

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.



Source link