ClingSTUN, a Linux backdoor that exploits unpatched internet-facing devices and converts them into persistent, remotely controlled proxy nodes.
The malware combines startup persistence, process concealment, competitor termination, and remote command execution with legitimate STUN infrastructure to support connectivity through network address translation.
The research published October 5 documents three campaign periods with changing payload servers and expanding exploitation capabilities.
Its defining feature is not a new vulnerability, but the integration of established exploitation techniques with public NAT-traversal services, allowing malicious communications to resemble ordinary VoIP and WebRTC traffic.
That distribution phase lasted two days before the attacker switched to 222[.]223[.]152[.]97. The latest observed download source was 118[.]145[.]196[.]225.
Subsequent activity targeted EnGenius cloud services through CVE-2025-34035 and D-Link UPnP through CVE-2024-23625, before broadening to Realtek SDK, TP-Link Archer AX21, AVTECH cameras, Linear access-control systems, and additional devices.

FortiGuard said in a report shared with GBhackers, the initial campaign delivered ClingSTUN from 124[.]163[.]212[.]119 through CVE-2022-36553, a command injection vulnerability affecting Hytec Inter HWL-2511-SS routers.
The expanding exploit set also included Ivanti appliances and Tenda equipment.
ClingSTUN Malware
One targeted vulnerability, CVE-2023-1389, enables unauthenticated command injection on vulnerable TP-Link Archer AX21 firmware.
CISA added it to its Known Exploited Vulnerabilities catalog on May 1, 2023, underscoring how previously documented weaknesses remain useful entry points for evolving malware campaigns.
Early downloaders execute architecture-specific payloads supporting ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64.
The third downloader adds aggressive cleanup, inspecting mounted paths and terminating processes associated with suspicious mounts or executables under /tmp.
ClingSTUN disables watchdog timers through ioctl operations against /dev/watchdog and /dev/misc/watchdog.
It also enumerates /proc, examines executable paths and command lines, and kills selected processes, including potential competitors operating from temporary directories.
For persistence, the backdoor copies itself to /root/.cling and /usr/local/bin/.cling, assigns executable permissions, and modifies /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot to launch during startup.
The malware then clears its original command-line arguments.
When running as root, it copies selected metadata from /proc/1/ into /tmp and bind-mounts that directory over its own process entry, obscuring process information behind data associated with the init process.

ClingSTUN binds a UDP socket to a random local port and sends standard 20-byte STUN binding requests.
The second evolution contacts 24 public endpoints and requires at least half to succeed; the third reduces the set to 13 and requires every endpoint connection to succeed.
Afterward, it periodically transmits its group identifier and mapped-port list to those endpoints.
Researchers did not identify separate coordination-server registration in this path, and how operators obtain mappings and deliver control traffic through NAT remains unverified.
A 20-byte operator packet activates additional functionality. Command 1 initiates an outbound TCP connection to a supplied endpoint, retrieves a command, and executes it. Seven embedded exploits additionally support self-propagation.
Defenders should correlate unexpected STUN traffic with recurring UDP keepalives, startup-file changes, hidden .cling binaries, and unusual process mounts.
Legitimate public STUN servers are not inherently attacker-controlled indicators. Accurate inventories, timely firmware updates, and reduced internet exposure directly address the campaign’s enabling conditions.
IOCs
| Type | Indicator |
|---|---|
| Host | 124[.]163[.]212[.]119 |
| Host | 222[.]223[.]152[.]97 |
| Host | 118[.]145[.]196[.]225 |
| File hash | dc892f5013edb0aa1e61e808511387373d8d120348b5be0929621d21e6e9946a |
| File hash | a297eddfa7abea8d411afc0f150f8f6f30e470a77204de87e3b0815fa9bb8a84 |
| File hash | 4fbd61cb9181ebbc4fe9a6e59d3c346dc00001da48d66bd890556fc6fad22b07 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

