ClingSTUN Linux proxy backdoor abusing IoT devices
Malware Activity
Summary
Hide ▲
Show ▼
The ClingSTUN Linux proxy backdoor is turning unpatched internet-facing IoT devices into remotely controlled proxy nodes, expanding covert infrastructure for abuse. The malware was tracked across three periods with different download servers and an expanding set of entry points. Its earliest observed wave relied on CVE-2022-36553 in Hytec Inter routers. Later activity added more flaws and used public STUN servers to keep infected systems reachable.
Related Happenings
Cling botnet with STUN-based C2 and persistence
Malware Activity
H score34
First: 05.10.2026 14:46
Last: 05.10.2026 14:46
Sources 1
How related:
ClingSTUN works as a back-connect proxy. It sends STUN binding requests to public servers, 24 in the second version and 13 in the third, to discover its external address and port mappings and keep NAT bindings open, then periodically reports its group identifier and mapped ports to the same servers.
About this happening:
The Cling malware activity now includes STUN-based back-connect proxying that uses public STUN servers to keep infected systems reachable as remotely controlled proxy...
Cling botnet with STUN-based C2 and persistence
Malware ActivityHow related: ClingSTUN works as a back-connect proxy. It sends STUN binding requests to public servers, 24 in the second version and 13 in the third, to discover its external address and port mappings and keep NAT bindings open, then periodically reports its group identifier and mapped ports to the same servers.
About this happening: The Cling malware activity now includes STUN-based back-connect proxying that uses public STUN servers to keep infected systems reachable as remotely controlled proxy...
AryStinger legacy-router reconnaissance and proxy network
Malware Activity
H score61
First: 22.06.2026 09:57
Last: 22.06.2026 09:57
Sources 1
About this happening:
The AryStinger malware family is building a distributed reconnaissance and proxy network from legacy routers and NAS appliances, expanding a covert relay layer that helps...
AryStinger legacy-router reconnaissance and proxy network
Malware ActivityAbout this happening: The AryStinger malware family is building a distributed reconnaissance and proxy network from legacy routers and NAS appliances, expanding a covert relay layer that helps...
AVRecon malware for Linux powering SocksEscort proxy network
Malware Activity
H score19
First: 12.03.2026 18:19
Last: 12.03.2026 18:19
Sources 1
About this happening:
The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
AVRecon malware for Linux powering SocksEscort proxy network
Malware ActivityAbout this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
Timeline
-
05.10.2026 17:30 2 articles · 1h ago
ClingSTUN turns unpatched IoT devices into proxy nodes
Initial DisclosureFortiGuard Labs reported ClingSTUN, a Linux proxy backdoor that abuses unpatched internet-facing IoT devices and legitimate public STUN servers to keep compromised systems reachable as remotely controlled proxy nodes. The campaign was tracked across three periods with different download servers; the first relied on CVE-2022-36553 in Hytec Inter routers, later waves added CVE-2025-34035 in EnGenius's IoT cloud service and CVE-2024-23625 in D-Link's UPnP service, and the third period expanded the list to 24 vulnerabilities. ClingSTUN also copies itself into system locations, modifies boot scripts for persistence, hides behind process information copied from init, and supports remote command execution.
Show sources
- ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes — www.infosecurity-magazine.com — 05.10.2026 17:30
- ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes — www.infosecurity-magazine.com — 05.10.2026 17:30