ClingSTUN Malware Turns Vulnerable IoT Devices Into Proxy Nodes

· Original article ↗

Summary

FortiGuard researchers identified ClingSTUN, Linux malware that exploits known IoT vulnerabilities, uses public STUN servers to map network reachability, and can spread to other vulnerable devices. Its operators’ control method remains unverified.

Key points

  • FortiGuard observed ClingSTUN attacks targeting at least 24 known vulnerabilities in IoT devices, including routers, surveillance systems, and industrial equipment.
  • The malware uses public STUN servers to discover infected devices’ external network mappings and reachable ports; researchers did not identify a traditional command-and-control server in this process.
  • ClingSTUN establishes persistence and includes exploits for seven additional vulnerabilities that can help it spread to other IoT devices.
  • Compromised devices can act as proxies, potentially exposing an enterprise’s public IP to blocklisting, reputational damage, bandwidth use, and operational disruption.
  • Recommended measures include inventorying affected devices, applying vendor updates, limiting internet exposure, segmenting IoT networks, and monitoring for unusual STUN traffic and UDP activity.
  • Blocking public STUN servers indiscriminately may disrupt legitimate services; detection should consider whether STUN activity is unexpected for a device’s role.

Article Details

Event Type
Discovery of ClingSTUN, a Linux malware strain exploiting known IoT vulnerabilities to compromise devices and use them as proxy nodes.
Impact
Compromised devices may relay attacker traffic through an enterprise's public IP address, creating risks of IP blocklisting, reputational damage, bandwidth consumption, operational disruption, and potential access to reachable internal destinations.

CVE

People

Malware

Vendors

China Mobilethe 24 that enable initial access and affect devices from Realtek, MVPower, TBK, Linksys, LB-LINK, China Mobile, and KGUARD. The oldest of these vulnerabilities is CVE-2014-8361 from 2014 in a Realtek device, andD-Linkrouters, network equipment, surveillance systems, and industrial systems from manufacturers that include D-Link, Realtek, Ivanti, and TP-Link.Ivantiequipment, surveillance systems, and industrial systems from manufacturers that include D-Link, Realtek, Ivanti, and TP-Link.KGUARDenable initial access and affect devices from Realtek, MVPower, TBK, Linksys, LB-LINK, China Mobile, and KGUARD. The oldest of these vulnerabilities is CVE-2014-8361 from 2014 in a Realtek device, and the most recentLB-LINKseparate from the 24 that enable initial access and affect devices from Realtek, MVPower, TBK, Linksys, LB-LINK, China Mobile, and KGUARD. The oldest of these vulnerabilities is CVE-2014-8361 from 2014 in a RealtekLinksysflaws are separate from the 24 that enable initial access and affect devices from Realtek, MVPower, TBK, Linksys, LB-LINK, China Mobile, and KGUARD. The oldest of these vulnerabilities is CVE-2014-8361 from 2014 in aMeiGThe most recent is a command injection flaw from earlier this year (CVE-2026-36356) that affects MeiG Smart FORGE_SLT711 devices.MVPowerThe flaws are separate from the 24 that enable initial access and affect devices from Realtek, MVPower, TBK, Linksys, LB-LINK, China Mobile, and KGUARD. The oldest of these vulnerabilities is CVE-2014-8361 from 2014 inRealteknetwork equipment, surveillance systems, and industrial systems from manufacturers that include D-Link, Realtek, Ivanti, and TP-Link.SunhilloThe oldest of the set is a long-patched command injection vulnerability from 2021 (CVE-2021-36380) in Sunhillo SureLine surveillance data distribution software used by the Federal Aviation Administration (FAA) and otherTBKThe flaws are separate from the 24 that enable initial access and affect devices from Realtek, MVPower, TBK, Linksys, LB-LINK, China Mobile, and KGUARD. The oldest of these vulnerabilities is CVE-2014-8361 from 2014 inTP-Linksystems, and industrial systems from manufacturers that include D-Link, Realtek, Ivanti, and TP-Link.

Products

Industries