Tuesday, October 6, 2026
Follow on LinkedIn

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote access.

Rather than simply infecting routers and cameras, it turns compromised equipment into remotely controlled proxy nodes that can relay traffic and run commands. The campaign targets known security flaws across multiple vendors, expanding its attack methods as it evolves.

Unpatched firmware, unsupported hardware, and exposed services create openings for infections that can survive device restarts and conceal their activity from routine checks. Fortinet researchers identified three stages of the campaign, each using a different download source.

Fortinet said in a report shared with Cyber Security News (CSN) that ClingSTUN combines vulnerability exploitation, startup persistence, and public networking services to maintain access to infected Linux devices.

The October 5 analysis describes a high-severity threat but does not provide an infection count or confirmed victim list.

Its findings show how ordinary connected equipment can become persistent attack infrastructure, with consequences extending beyond the device originally compromised.

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities

Researchers first observed delivery through CVE-2022-36553, a command injection flaw in Hytec Inter HWL-2511-SS routers.

That initial stage lasted only two days before the attackers changed download infrastructure and broadened their exploitation strategy to reach additional vulnerable products.

The second stage targeted the EnGenius cloud service vulnerability CVE-2025-34035 and D-Link UPnP flaw CVE-2024-23625. Later activity added Realtek, Linear, TP-Link, AVTECH, and other devices, showing that the operators were not relying on one manufacturer or a single entry point.

The second-evolution downloader script, 'wget.sh' (Source - Fortinet)
The second-evolution downloader script, ‘wget.sh’ (Source – Fortinet)

Among those targets was CVE-2023-1389 in TP-Link Archer AX21 routers. Earlier reporting on TP-Link command injection attacks documented exploitation of the same weakness, illustrating how familiar vulnerabilities remain useful to attackers when exposed devices stay unpatched.

The campaign also exploited CVE-2024-7029 in AVTECH AVM1203 cameras, a weakness previously associated with Mirai attacks against cameras in another campaign. The overlap concerns reused vulnerabilities, not evidence that ClingSTUN belongs to the same malware family or shares those operators.

Downloaders retrieve versions for ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64 systems. The newest downloader also removes certain process-related mounts and terminates processes running from temporary storage, helping clear competing activity before the backdoor establishes itself.

ClingSTUN then creates hidden executable copies and modifies three startup files so it runs during boot. It also disables watchdog timers and kills selected processes, combining persistence with interference against programs that could compete with it on the infected device.

Public STUN Services Conceal Connectivity

ClingSTUN clears its command-line arguments to make ordinary process listings less informative. When running with administrator privileges, it overlays its process information with metadata copied from the system’s initial process.

Similar Linux malware process concealment techniques highlight why appearance alone cannot establish whether a process is legitimate.

The backdoor uses STUN, a protocol commonly involved in internet calls and browser communications, to discover external address and port mappings.

The analyzed second version contacted 24 public endpoints; the third reduced that number to 13 and required successful connections to every endpoint. A 20-byte operator packet can activate remote command execution or self-propagation.

One command directs an outbound TCP connection to a specified endpoint, where the malware receives instructions to execute. Researchers identified seven built-in vulnerability exploits supporting further spread to routers and recording equipment.

Killing competitor processes (Source - Fortinet)
Killing competitor processes (Source – Fortinet)

However, researchers could not verify how operators obtain the external mappings and deliver control traffic through network address translation. Public STUN servers should not automatically be treated as malicious infrastructure.

Defenders should instead correlate these connections with suspicious processes, unexpected UDP activity, and recurring keepalive traffic.

Fortinet recommends inventorying internet-facing devices, tracking firmware support, and promptly patching actively exploited vulnerabilities.

Unsupported equipment should be replaced or isolated, while unnecessary exposed services should be restricted. Monitoring startup changes alongside unusual network behavior helps identify devices that have become persistent backdoors.

The indicators below reproduce campaign hosts, hashes, and observed artifacts from the source. Public STUN endpoints provide investigative context and are not confirmed attacker-controlled infrastructure.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Campaign IPv4124[.]163[.]212[.]119First-stage malware delivery host.
Campaign IPv4222[.]223[.]152[.]97Second-stage malware download host.
Campaign IPv4118[.]145[.]196[.]225Third-stage malware download host.
SHA-256dc892f5013edb0aa1e61e808511387373d8d120348b5be0929621d21e6e9946aFile hash listed in the source’s campaign IoCs.
SHA-256a297eddfa7abea8d411afc0f150f8f6f30e470a77204de87e3b0815fa9bb8a84File hash listed in the source’s campaign IoCs.
SHA-2564fbd61cb9181ebbc4fe9a6e59d3c346dc00001da48d66bd890556fc6fad22b07File hash listed in the source’s campaign IoCs.
SHA-256121f2050e3c891b29565fd73451fff7ae60199c86eb8d79ec1eb1d9844578487File hash listed in the source’s campaign IoCs.
SHA-25648f9b72ce72ab7087794650d6eef10135345088384fbde1482f1c74a02b80302File hash listed in the source’s campaign IoCs.
SHA-256e6e113783356446aef66e5296db45b244f318292af7cebc2a9bd76f095a95c4cFile hash listed in the source’s campaign IoCs.
SHA-256c1d8e2829ea63b9dc1cf2c3421a5093406adad4d6622e238376e78e908e0e6e8File hash listed in the source’s campaign IoCs.
SHA-25648962b3893f2c8261e32e6b95ea7d463d145a529a8b2a6c987dd979454405c73File hash listed in the source’s campaign IoCs.
SHA-25676692a23abe718b93e63edefd743971ec627c0cdf3778f856bd5ec88003deaa2File hash listed in the source’s campaign IoCs.
SHA-256ec199c78c11040fd3127887222fd75a85e5797bf96aa691a117fdd83dd663d81File hash listed in the source’s campaign IoCs.
SHA-256c0d8ffebfba969b1c1ca76bd9623bb623e9f95155c8ceca77d8fcc521435a497File hash listed in the source’s campaign IoCs.
SHA-256f49f45303cbfccee14ff193ac9608f860e6d616f08c0ecbef1ec44f7c863d7ecFile hash listed in the source’s campaign IoCs.
SHA-2569391c6ad17aced1142607c0c623b18d86a7697cc483d204ffac94093e26b8068File hash listed twice in the source; reproduced once here.
SHA-256e4d12208789f36efc5a1ff765088fed95d6bb5972d1a804a4536fd42366797d4File hash listed in the source’s campaign IoCs.
SHA-256284e5ec8748f99fd1b8c331b699a5fe5fd4448bbaae0347a940f427f931c4d14File hash listed in the source’s campaign IoCs.
SHA-2566581bf37184bb2db899b9893064d39dd314ea691adf3281cc0aa7e0a31e5138aFile hash listed in the source’s campaign IoCs.
SHA-25610d83c1748895361e07320f68d44d427b43cadd2cbffe0ab5e607ab03aec83daFile hash listed in the source’s campaign IoCs.
SHA-2562ed54e0f988a62039abed88f6394eb1e3d5ed931f0183556055417fb08844ecfFile hash listed in the source’s campaign IoCs.
SHA-256b90640b392827b4f2d280f6cf67860862953331917d42df23e1653a92f2f98adFile hash listed in the source’s campaign IoCs.
SHA-256dfba6008a2c828a9cb62342aec53006ae05a60cb8d4c41c3fa216fd727e8c6a3File hash listed in the source’s campaign IoCs.
SHA-2565c4e263546fb21f8fe8732789a5b6583eaa8ae11ebeef099462a7c9bf50e022dFile hash listed in the source’s campaign IoCs.
File namewget.shDownloader script identified in the second and third stages.
File namem.x86_64Analyzed second-stage AMD x86-64 malware executable.
File namex86_64Analyzed third-stage AMD x86-64 malware executable.
Malware path/root/.clingHidden executable copy created for persistence.
Malware path/usr/local/bin/.clingAdditional hidden executable copy created for persistence.
Persistence target/etc/inittabLegitimate startup file modified to launch the malware.
Persistence target/etc/init.d/rcSLegitimate startup script modified for boot execution.
Persistence target/etc/rc.d/rc.bootLegitimate boot file modified for persistence.
Behavioral context/tmpDownload, execution, process-termination, and concealment location; not a standalone IoC.
Behavioral context/var/tmpDirectory checked when selecting processes for termination; not a standalone IoC.
Behavioral context/proc/mountsMount information examined by the third-stage downloader.
Behavioral context/procProcess information directory enumerated by the malware.
Behavioral context/proc/<pid>/cmdlineProcess command-line information checked during process termination.
Behavioral context/proc/<pid>/exeExecutable reference inspected during process termination.
Behavioral context/proc/1/Source of legitimate process metadata copied for concealment.
Behavioral context/proc/<pid>Malware process directory overlaid to conceal its information.
Behavioral context/dev/watchdogLegitimate watchdog interface manipulated by the malware.
Behavioral context/dev/misc/watchdogAdditional legitimate watchdog interface manipulated by the malware.
Exploit target filecard_scan_decoder.phpLinear eMerge entry point; not a standalone compromise indicator.
Exploit target filepopen.cgiHytec router entry point; not a standalone compromise indicator.
Exploit target fileFactory.cgiAVTECH camera entry point; not a standalone compromise indicator.
Exploit target fileaccount_mgr.cgiD-Link entry point; not a standalone compromise indicator.
Exploit target componentluci.stokTP-Link Archer AX21 entry point identified in the source.
Exploit target componenthnap_mainD-Link Go-RT-AC750 component targeted through a buffer overflow.
Public STUN IPv45[.]39[.]72[.]109Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv477[.]72[.]169[.]213Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4154[.]73[.]34[.]8Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv420[.]14[.]234[.]56Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv481[.]187[.]30[.]115Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4185[.]125[.]180[.]70Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv464[.]131[.]63[.]217Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv482[.]113[.]193[.]63Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4207[.]38[.]82[.]134Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv466[.]51[.]128[.]1Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv483[.]211[.]9[.]232Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4212[.]53[.]40[.]43Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv474[.]125[.]250[.]129Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv485[.]17[.]88[.]164Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4212[.]227[.]67[.]33Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv477[.]72[.]169[.]210Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv485[.]93[.]219[.]114Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4212[.]227[.]67[.]34Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv477[.]72[.]169[.]211Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4139[.]162[.]62[.]29Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4216[.]93[.]246[.]18Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv477[.]72[.]169[.]212Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4145[.]249[.]115[.]184Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4217[.]0[.]0[.]249Contacted public endpoint; not confirmed attacker-controlled.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

Tushar Subhra Dutta
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
0-Hour Cyber Security Alerts!
Get the latest Cyber security News sent directly to your inbox.

Cyber Security Guide

Latest Cyber News

Expert Talks