ClingSTUN Malware Compromises Unpatched IoT Devices as Proxy Nodes
A new Linux proxy backdoor called ClingSTUN is targeting vulnerable internet-facing devices and abusing public STUN servers to maintain remote access.
FTMQ Security, written by our newsroom0 views

A Linux proxy backdoor known as ClingSTUN is exploiting known flaws in internet-facing internet-of-things devices to convert them into remotely controlled proxy nodes, according to reports from Dark Reading, InfoSecurity Magazine, and Hackread. InfoSecurity Magazine reported that FortiGuard Labs published research on October 5 detailing the campaign. [1][2][4]
Dark Reading and Hackread both report that the malware exploits 24 known vulnerabilities to compromise devices. The attackers use legitimate public STUN servers to hide their communications and maintain access, according to Dark Reading and InfoSecurity Magazine. Cybersecuritynews.com reported that the malware disguises its traffic as Google STUN communications. [1][2][3][4]
InfoSecurity Magazine reported that FortiGuard Labs tracked the operation across three distinct periods, with each phase using a different download server. The initial stage lasted two days and targeted CVE-2022-36553 in Hytec Inter routers, before attackers expanded to exploit additional flaws including CVE-2025-34035 in EnGenius cloud services. [2]
In computer networking, a proxy server functions as an intermediary application between a requesting client and the server supplying the resource. [5]
In short
- ClingSTUN is a Linux proxy backdoor targeting internet-facing IoT devices.
- The malware exploits 24 known vulnerabilities to compromise systems.
- Attackers abuse public STUN servers to keep compromised devices reachable as proxy nodes.
- FortiGuard Labs tracked the campaign across three distinct phases using different download servers.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]ClingSTUN Turns Vulnerable IoT Devices Into Proxy NodesDark Reading, 17h ago (the report this story comes from)
- [2]ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy NodesInfoSecurity Magazine, 1d ago
- [3]Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devicescybersecuritynews.com, 1d ago
- [4]Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux BackdoorHackread, 22h ago
Background
- [5]Proxy server on Wikipedia
Our newsroom writes these reports with the help of software, from the 5 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy NodesData Breaches, 16h ago
More in Top Stories
- ShinyHunters exploits PeopleSoft zero day hole as FBI arrests suspected member13h ago
- OpenAI introduces invisible text watermarking for ChatGPT and Codex in EU14h ago
- Microsoft Patches High Severity Privilege Escalation Flaw in Exchange Server16h ago
- Hackers target Rejetto HFS servers following critical session forgery vulnerability discovery16h ago
- China Aligned TA419 Targets US AI Experts With Phishing Attacks1d ago
- Citrix issues emergency updates for NetScaler zero day vulnerability1d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.