ClingSTUN: New Backdoor Turns IoT Devices Into Persistent Attack Proxies

A newly uncovered Linux backdoor dubbed “ClingSTUN” poses a serious risk by exploiting multiple IoT vulnerabilities to gain long-term remote access. It’s not just about infecting routers or cameras—this threat enables attackers to turn insecure devices into proxy nodes capable of relaying traffic and executing commands, while evading detection even after reboots. October 5 marks the publication date of the analysis that revealed this evolving campaign.

How ClingSTUN Works: Entry Points, Persistence, and Stealth

The campaign kicks off by exploiting known flaws in internet-connected devices. Its initial stage leveraged CVE-2022-36553, a command injection vulnerability in Hytec routers. Shortly after, attackers broadened their scope to include faults like CVE-2025-34035 in EnGenius’ cloud platform, CVE-2024-23625 in D-Link’s UPnP implementation, and others in Realtek, Linear, TP-Link, AVTECH hardware—among them, CVE-2023-1389 in TP-Link Archer AX21 routers, and CVE-2024-7029 affecting AVTECH AVM1203 cameras.

ClingSTUN supports diverse architectures—including ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64. The newer versions of its downloader script remove certain process mounts and kill processes running from temporary directories, presumably to suppress rival malware. For persistence, it installs hidden executables in folders like /root/.clingand modifies system startup scripts—such as /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot—so it launches at boot. It also tampers with watchdog timers and terminates selected system processes to avoid competition.

Using STUN Services to Mask Remote Control

To help disguise its network activity, ClingSTUN makes use of public STUN endpoints (the protocol often used for VoIP and browser apps) to find external IP and port mappings. Its second version contacts around 24 public STUN servers; a third version trims that down to 13. The backdoor expects successful responses from all its configured endpoints before moving forward. Once activated, a 20-byte payload can trigger remote command execution or enable propagation.

In terms of concealment, it wipes command-line arguments to avoid exposing itself in process listings. In privileged operations, it may overlay its process metadata with that of the system’s init process (PID 1), further masking its presence.

Indicators & Defense: What to Look For

There is no confirmed victim list or infection count yet, but the advisory lists several Indicators of Compromise (IoCs) including download hosts, IPv4 addresses, file hashes (SHA-256), hidden paths, compromised startup files, and use of directories like /tmp, /var/tmp, and /proc.

Organizations should move quickly to inventory all internet-facing devices, check firmware support status, and apply patches for actively exploited vulnerabilities. For outdated hardware, replacement or network isolation is recommended. Also, monitoring for unauthorized startup script changes and unusual network traffic—especially UDP chatter, persistent connections, and repeated keepalives—can help detect ClingSTUN’s activity.

ClingSTUN’s threat is rated high severity. It highlights a growing trend: ordinary, under-maintained devices can become the backbone of long-running campaigns with impact far beyond individual compromised units. This underscores the urgency of treating all networked devices—not just full computers—as essential components in security strategy.

Why it matters: ClingSTUN shows how neglected IoT devices are increasingly leveraged as persistent infrastructure in cyberattacks. As the number of exposed services and unpatched vulnerabilities continues to grow, so do the entry points for advanced threats. To stay ahead, defenders must expand visibility, improve asset management, and tighten both firmware hygiene and network exposure. Watch for evolving exploit stages, new targeted manufacturers, and attempts to blend malicious traffic into normal STUN-based flows.