ClingSTUN Exploits More Than 24 Vulnerabilities to Compromise Linux Devices and Turn Them into Proxies

Views: 43 views

549/69 Tuesday, October 6, 2026

Researchers from FortiGuard Labs have disclosed the discovery of ClingSTUN malware on Linux systems, targeting internet-exposed devices by exploiting previously disclosed but unpatched vulnerabilities to gain access. Researchers found that the attackers exploited 24 vulnerabilities affecting products from multiple vendors, including D-Link, TP-Link, Ivanti, Realtek, Tenda, and AVTECH, before installing ClingSTUN to turn compromised devices into attacker-controlled proxies. The threat actors were also observed continuously adding and modifying the vulnerabilities used in their attacks.

Once installed, ClingSTUN establishes persistence so that the malware restarts when the device boots, terminates other malware already running on the system, and supports command execution from the attackers. A notable feature is its use of the STUN (Session Traversal Utilities for NAT) protocol to identify externally reachable IP addresses and ports, helping maintain connectivity through NAT by using commonly available public STUN servers. As a result, malicious traffic may blend in with legitimate VoIP or WebRTC activity. The malware also contains exploits for seven additional vulnerabilities, allowing it to scan for and spread to other vulnerable devices.

Administrators should review internet-exposed devices and promptly apply firmware and security updates for affected vulnerabilities. Unnecessary externally accessible services should also be disabled or restricted. Devices that have reached end of support and can no longer receive security updates should be isolated from the network or replaced. Administrators should also monitor for abnormal processes, UDP connections, and persistent STUN traffic in combination with other suspicious behavior. Because legitimate applications may also communicate with STUN servers, STUN traffic alone should not be treated as confirmation that a device is infected.

Source: https://www.securityweek.com/linux-backdoor-abuses-stun-protocol-exploits-dozens-of-flaws/