ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes
A newly identified Linux proxy malware is exploiting known Internet of Things vulnerabilities and public STUN servers to build remote proxy networks.
FTMQ Security, written by our newsroom0 views

A Linux proxy backdoor named ClingSTUN is exploiting known vulnerabilities in internet-facing Internet of Things devices to turn compromised systems into remotely controlled proxy nodes. InfoSecurity Magazine, Dark Reading, and Hackread all report that the malware targets unpatched flaws, while InfoSecurity Magazine and Dark Reading add that it abuses legitimate public STUN servers to keep communications reachable and obscured. [1][2][4]
According to Dark Reading and Hackread, the malware campaign targets a total of 24 known vulnerabilities. InfoSecurity Magazine reported that research from FortiGuard Labs, published on October 5, tracked the campaign across three distinct phases using different download servers. The first phase relied on CVE-2022-36553 in Hytec Inter routers, while the second phase expanded to CVE-2025-34035 in EnGenius IoT cloud services and CVE-2024-23625 in D-Link UPnP services. [1][2][4]
As cybersecuritynews.com reported, the malware also disguises its control traffic as Google STUN traffic to control compromised devices. Ipidea, a Chinese company, previously operated a large residential proxy network that controlled millions of consumer devices for proxy use, according to Wikipedia. [3][5]
As FTMQ Security reported earlier, the malware continues to abuse public infrastructure to maintain persistent remote access across infected endpoints. Organizations are advised to apply security patches for exposed IoT hardware to block initial exploitation vectors. [1][6]
In short
- ClingSTUN is a Linux backdoor that targets unpatched Internet of Things devices.
- The campaign exploits 24 known flaws, including CVE-2022-36553, CVE-2025-34035, and CVE-2024-23625.
- The malware abuses public STUN servers to maintain proxy access to compromised nodes.
- FortiGuard Labs tracked the ClingSTUN campaign across three distinct deployment phases.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy NodesInfoSecurity Magazine, 1d ago (the report this story comes from)
- [2]ClingSTUN Turns Vulnerable IoT Devices Into Proxy NodesDark Reading, 17h ago
- [3]Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devicescybersecuritynews.com, 1d ago
- [4]Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux BackdoorHackread, 22h ago
Background
- [5]Ipidea on Wikipedia
- [6]ClingSTUN Malware Compromises Unpatched IoT Devices as Proxy Nodes FTMQ Security, 16h ago
Our newsroom writes these reports with the help of software, from the 6 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- ClingSTUN Malware Compromises Unpatched IoT Devices as Proxy NodesTop Stories, 16h ago
More in Data Breaches
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.