Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClingSTUN Linux proxy backdoor abusing IoT devices

Malware Activity
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

The ClingSTUN Linux proxy backdoor is turning unpatched internet-facing IoT devices into remotely controlled proxy nodes, expanding covert infrastructure for abuse. The malware was tracked across three periods with different download servers and an expanding set of entry points. Its earliest observed wave relied on CVE-2022-36553 in Hytec Inter routers. Later activity added more flaws and used public STUN servers to keep infected systems reachable.

Related Happenings

Cling botnet with STUN-based C2 and persistence

Malware Activity
H score34 First: 05.10.2026 14:46 Last: 05.10.2026 14:46 Sources 1

How related: ClingSTUN works as a back-connect proxy. It sends STUN binding requests to public servers, 24 in the second version and 13 in the third, to discover its external address and port mappings and keep NAT bindings open, then periodically reports its group identifier and mapped ports to the same servers.

About this happening: The Cling malware activity now includes STUN-based back-connect proxying that uses public STUN servers to keep infected systems reachable as remotely controlled proxy...

AryStinger legacy-router reconnaissance and proxy network

Malware Activity
H score61 First: 22.06.2026 09:57 Last: 22.06.2026 09:57 Sources 1

About this happening: The AryStinger malware family is building a distributed reconnaissance and proxy network from legacy routers and NAS appliances, expanding a covert relay layer that helps...

AVRecon malware for Linux powering SocksEscort proxy network

Malware Activity
H score19 First: 12.03.2026 18:19 Last: 12.03.2026 18:19 Sources 1

About this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...

Timeline

  1. 05.10.2026 17:30 2 articles · 1h ago

    ClingSTUN turns unpatched IoT devices into proxy nodes

    Initial Disclosure

    FortiGuard Labs reported ClingSTUN, a Linux proxy backdoor that abuses unpatched internet-facing IoT devices and legitimate public STUN servers to keep compromised systems reachable as remotely controlled proxy nodes. The campaign was tracked across three periods with different download servers; the first relied on CVE-2022-36553 in Hytec Inter routers, later waves added CVE-2025-34035 in EnGenius's IoT cloud service and CVE-2024-23625 in D-Link's UPnP service, and the third period expanded the list to 24 vulnerabilities. ClingSTUN also copies itself into system locations, modifies boot scripts for persistence, hides behind process information copied from init, and supports remote command execution.

    Show sources