ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote access.
Rather than simply infecting routers and cameras, it turns compromised equipment into remotely controlled proxy nodes that can relay traffic and run commands. The campaign targets known security flaws across multiple vendors, expanding its attack methods as it evolves.
Unpatched firmware, unsupported hardware, and exposed services create openings for infections that can survive device restarts and conceal their activity from routine checks. Fortinet researchers identified three stages of the campaign, each using a different download source.
Fortinet said in a report shared with Cyber Security News (CSN) that ClingSTUN combines vulnerability exploitation, startup persistence, and public networking services to maintain access to infected Linux devices.
The October 5 analysis describes a high-severity threat but does not provide an infection count or confirmed victim list.
Its findings show how ordinary connected equipment can become persistent attack infrastructure, with consequences extending beyond the device originally compromised.
ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities
Researchers first observed delivery through CVE-2022-36553, a command injection flaw in Hytec Inter HWL-2511-SS routers.
That initial stage lasted only two days before the attackers changed download infrastructure and broadened their exploitation strategy to reach additional vulnerable products.
The second stage targeted the EnGenius cloud service vulnerability CVE-2025-34035 and D-Link UPnP flaw CVE-2024-23625. Later activity added Realtek, Linear, TP-Link, AVTECH, and other devices, showing that the operators were not relying on one manufacturer or a single entry point.
.webp)
Among those targets was CVE-2023-1389 in TP-Link Archer AX21 routers. Earlier reporting on TP-Link command injection attacks documented exploitation of the same weakness, illustrating how familiar vulnerabilities remain useful to attackers when exposed devices stay unpatched.
The campaign also exploited CVE-2024-7029 in AVTECH AVM1203 cameras, a weakness previously associated with Mirai attacks against cameras in another campaign. The overlap concerns reused vulnerabilities, not evidence that ClingSTUN belongs to the same malware family or shares those operators.
Downloaders retrieve versions for ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64 systems. The newest downloader also removes certain process-related mounts and terminates processes running from temporary storage, helping clear competing activity before the backdoor establishes itself.
ClingSTUN then creates hidden executable copies and modifies three startup files so it runs during boot. It also disables watchdog timers and kills selected processes, combining persistence with interference against programs that could compete with it on the infected device.
Public STUN Services Conceal Connectivity
ClingSTUN clears its command-line arguments to make ordinary process listings less informative. When running with administrator privileges, it overlays its process information with metadata copied from the system’s initial process.
Similar Linux malware process concealment techniques highlight why appearance alone cannot establish whether a process is legitimate.
The backdoor uses STUN, a protocol commonly involved in internet calls and browser communications, to discover external address and port mappings.
The analyzed second version contacted 24 public endpoints; the third reduced that number to 13 and required successful connections to every endpoint. A 20-byte operator packet can activate remote command execution or self-propagation.
One command directs an outbound TCP connection to a specified endpoint, where the malware receives instructions to execute. Researchers identified seven built-in vulnerability exploits supporting further spread to routers and recording equipment.
.webp)
However, researchers could not verify how operators obtain the external mappings and deliver control traffic through network address translation. Public STUN servers should not automatically be treated as malicious infrastructure.
Defenders should instead correlate these connections with suspicious processes, unexpected UDP activity, and recurring keepalive traffic.
Fortinet recommends inventorying internet-facing devices, tracking firmware support, and promptly patching actively exploited vulnerabilities.
Unsupported equipment should be replaced or isolated, while unnecessary exposed services should be restricted. Monitoring startup changes alongside unusual network behavior helps identify devices that have become persistent backdoors.
The indicators below reproduce campaign hosts, hashes, and observed artifacts from the source. Public STUN endpoints provide investigative context and are not confirmed attacker-controlled infrastructure.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Campaign IPv4 | 124[.]163[.]212[.]119 | First-stage malware delivery host. |
| Campaign IPv4 | 222[.]223[.]152[.]97 | Second-stage malware download host. |
| Campaign IPv4 | 118[.]145[.]196[.]225 | Third-stage malware download host. |
| SHA-256 | dc892f5013edb0aa1e61e808511387373d8d120348b5be0929621d21e6e9946a | File hash listed in the source’s campaign IoCs. |
| SHA-256 | a297eddfa7abea8d411afc0f150f8f6f30e470a77204de87e3b0815fa9bb8a84 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | 4fbd61cb9181ebbc4fe9a6e59d3c346dc00001da48d66bd890556fc6fad22b07 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | 121f2050e3c891b29565fd73451fff7ae60199c86eb8d79ec1eb1d9844578487 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | 48f9b72ce72ab7087794650d6eef10135345088384fbde1482f1c74a02b80302 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | e6e113783356446aef66e5296db45b244f318292af7cebc2a9bd76f095a95c4c | File hash listed in the source’s campaign IoCs. |
| SHA-256 | c1d8e2829ea63b9dc1cf2c3421a5093406adad4d6622e238376e78e908e0e6e8 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | 48962b3893f2c8261e32e6b95ea7d463d145a529a8b2a6c987dd979454405c73 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | 76692a23abe718b93e63edefd743971ec627c0cdf3778f856bd5ec88003deaa2 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | ec199c78c11040fd3127887222fd75a85e5797bf96aa691a117fdd83dd663d81 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | c0d8ffebfba969b1c1ca76bd9623bb623e9f95155c8ceca77d8fcc521435a497 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | f49f45303cbfccee14ff193ac9608f860e6d616f08c0ecbef1ec44f7c863d7ec | File hash listed in the source’s campaign IoCs. |
| SHA-256 | 9391c6ad17aced1142607c0c623b18d86a7697cc483d204ffac94093e26b8068 | File hash listed twice in the source; reproduced once here. |
| SHA-256 | e4d12208789f36efc5a1ff765088fed95d6bb5972d1a804a4536fd42366797d4 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | 284e5ec8748f99fd1b8c331b699a5fe5fd4448bbaae0347a940f427f931c4d14 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | 6581bf37184bb2db899b9893064d39dd314ea691adf3281cc0aa7e0a31e5138a | File hash listed in the source’s campaign IoCs. |
| SHA-256 | 10d83c1748895361e07320f68d44d427b43cadd2cbffe0ab5e607ab03aec83da | File hash listed in the source’s campaign IoCs. |
| SHA-256 | 2ed54e0f988a62039abed88f6394eb1e3d5ed931f0183556055417fb08844ecf | File hash listed in the source’s campaign IoCs. |
| SHA-256 | b90640b392827b4f2d280f6cf67860862953331917d42df23e1653a92f2f98ad | File hash listed in the source’s campaign IoCs. |
| SHA-256 | dfba6008a2c828a9cb62342aec53006ae05a60cb8d4c41c3fa216fd727e8c6a3 | File hash listed in the source’s campaign IoCs. |
| SHA-256 | 5c4e263546fb21f8fe8732789a5b6583eaa8ae11ebeef099462a7c9bf50e022d | File hash listed in the source’s campaign IoCs. |
| File name | wget.sh | Downloader script identified in the second and third stages. |
| File name | m.x86_64 | Analyzed second-stage AMD x86-64 malware executable. |
| File name | x86_64 | Analyzed third-stage AMD x86-64 malware executable. |
| Malware path | /root/.cling | Hidden executable copy created for persistence. |
| Malware path | /usr/local/bin/.cling | Additional hidden executable copy created for persistence. |
| Persistence target | /etc/inittab | Legitimate startup file modified to launch the malware. |
| Persistence target | /etc/init.d/rcS | Legitimate startup script modified for boot execution. |
| Persistence target | /etc/rc.d/rc.boot | Legitimate boot file modified for persistence. |
| Behavioral context | /tmp | Download, execution, process-termination, and concealment location; not a standalone IoC. |
| Behavioral context | /var/tmp | Directory checked when selecting processes for termination; not a standalone IoC. |
| Behavioral context | /proc/mounts | Mount information examined by the third-stage downloader. |
| Behavioral context | /proc | Process information directory enumerated by the malware. |
| Behavioral context | /proc/<pid>/cmdline | Process command-line information checked during process termination. |
| Behavioral context | /proc/<pid>/exe | Executable reference inspected during process termination. |
| Behavioral context | /proc/1/ | Source of legitimate process metadata copied for concealment. |
| Behavioral context | /proc/<pid> | Malware process directory overlaid to conceal its information. |
| Behavioral context | /dev/watchdog | Legitimate watchdog interface manipulated by the malware. |
| Behavioral context | /dev/misc/watchdog | Additional legitimate watchdog interface manipulated by the malware. |
| Exploit target file | card_scan_decoder.php | Linear eMerge entry point; not a standalone compromise indicator. |
| Exploit target file | popen.cgi | Hytec router entry point; not a standalone compromise indicator. |
| Exploit target file | Factory.cgi | AVTECH camera entry point; not a standalone compromise indicator. |
| Exploit target file | account_mgr.cgi | D-Link entry point; not a standalone compromise indicator. |
| Exploit target component | luci.stok | TP-Link Archer AX21 entry point identified in the source. |
| Exploit target component | hnap_main | D-Link Go-RT-AC750 component targeted through a buffer overflow. |
| Public STUN IPv4 | 5[.]39[.]72[.]109 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 77[.]72[.]169[.]213 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 154[.]73[.]34[.]8 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 20[.]14[.]234[.]56 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 81[.]187[.]30[.]115 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 185[.]125[.]180[.]70 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 64[.]131[.]63[.]217 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 82[.]113[.]193[.]63 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 207[.]38[.]82[.]134 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 66[.]51[.]128[.]1 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 83[.]211[.]9[.]232 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 212[.]53[.]40[.]43 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 74[.]125[.]250[.]129 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 85[.]17[.]88[.]164 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 212[.]227[.]67[.]33 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 77[.]72[.]169[.]210 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 85[.]93[.]219[.]114 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 212[.]227[.]67[.]34 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 77[.]72[.]169[.]211 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 139[.]162[.]62[.]29 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 216[.]93[.]246[.]18 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 77[.]72[.]169[.]212 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 145[.]249[.]115[.]184 | Contacted public endpoint; not confirmed attacker-controlled. |
| Public STUN IPv4 | 217[.]0[.]0[.]249 | Contacted public endpoint; not confirmed attacker-controlled. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
