ClingSTUN: Linux backdoor turns IoT gear into proxies
ClingSTUN exploits 24 known flaws in routers, DVRs and Ivanti gateways, then hides its control channel in public STUN traffic. CVEs, IOCs and cleanup.
By Yaali. October 6, 2026, 6 min read, Threat intel, Vulnerabilities, Patching.
FortiGuard Labs published an analysis on October 5 of ClingSTUN, a Linux back-connect proxy backdoor that its operators install through 24 known vulnerabilities in routers, DVRs, NAS boxes, UPnP stacks and Ivanti Connect Secure gateways. A back-connect proxy is a bot that dials out to its operator and then relays the operator's traffic, so the attacker's activity leaves the internet from your public IP address. ClingSTUN also carries seven more exploits that it uses to infect neighbouring devices on its own.
Nozomi Networks described the same malware, which it calls Cling, on October 1, after a spike in exploitation of a Realtek SDK flaw that started around September 5. If you have Tenda or D-Link routers, AVTECH cameras, older D-Link NAS units or an Ivanti gateway that was patched late, check them this week. Fortinet has not named the operators, said how many devices are infected or named any victims.

How it works
The operators get in mostly through command injection: a web page or UPnP handler on the device passes a request parameter to the shell without filtering it. The injected command runs a downloader script (wget.sh in later versions) that fetches a build for the device's processor: x86-64, ARM, i386, MIPS or PowerPC.
Once running, the bot copies itself to /root/.cling and /usr/local/bin/.cling and appends both to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot, the boot scripts used by SysV and BusyBox init systems. It opens /dev/watchdog or /dev/misc/watchdog and turns off the hardware watchdog timer, which would otherwise reboot the device if the system stopped responding. It kills other processes running from /tmp or /var/tmp, where rival botnets usually live. To hide, it wipes its own command line and bind-mounts /tmp over its /proc/<pid> directory, so tools such as ps show the details of PID 1, the init process, instead.
STUN (Session Traversal Utilities for NAT) is the protocol that VoIP phones and WebRTC video calls use to ask a public server "what address and port do you see me on?" so they can receive traffic through NAT. ClingSTUN sends 20-byte STUN binding requests from a UDP socket on a random local port to a list of public STUN servers. Early builds used 24 servers and the third version 13, and at least half must answer. The replies give the bot its public IP and port, and the steady traffic keeps that NAT mapping open, so the operator can reach the device on the same socket.
The bot then sends periodic keepalives carrying a group identifier and its mapped ports. When a 20-byte packet from the operator arrives on that socket, the bot opens an outbound TCP connection to an address the operator chooses and executes the commands it receives. Nozomi adds that commands sit in the 12-byte STUN transaction ID field, which the standard says should be random and which Cling sets to all zeros in its own requests. It also found command packets that appeared to come from 74.125.250.129, an address behind Google's stun.l.google.com. Differences in IP time-to-live values suggest the operator spoofed that source address rather than using Google's servers. Nozomi lists the commands as scanning and spreading, starting and stopping a TCP tunnel or proxy, and denial-of-service attacks.
What attackers are doing
Fortinet splits the campaign into three periods, each with its own download host. Period one lasted two days, served from 124.163.212.119, and used a single Hytec HWL-2511-SS flaw (CVE-2022-36553). Period two moved to 222.223.152.97 and added EnGenius, D-Link UPnP and other bugs. Period three, served from 118.145.196.225, brought the list to 24, including Ivanti Connect Secure CVE-2023-46805 (authentication bypass, CVSS 8.2) and CVE-2024-21887 (command injection, CVSS 9.1).
The full initial-access list, by vendor:
- Tenda
exeCommandinjection: CVE-2024-46048, CVE-2024-35340, CVE-2024-32314, CVE-2024-32292, CVE-2024-32281, CVE-2022-35555, CVE-2022-26289 - D-Link: CVE-2024-23625, CVE-2024-23624 and CVE-2019-17621 (UPnP), CVE-2022-37055 (Go-RT-AC750), CVE-2024-10914 and CVE-2024-10915 (NAS
account_mgr.cgi) - Ivanti Connect Secure and Policy Secure: CVE-2023-46805, CVE-2024-21887
- One each: Hytec CVE-2022-36553, EnGenius CVE-2025-34035, Linear eMerge CVE-2019-7256, Realtek SDK CVE-2021-35394 (CVSS 9.8), TP-Link Archer AX21 CVE-2023-1389, Sunhillo SureLine CVE-2021-36380, AVTECH AVM1203 CVE-2024-7029, MeiG FORGE_SLT711 CVE-2026-36356, Lantronix EDS5000 CVE-2025-67038
The seven exploits built into the bot for spreading are CVE-2014-8361 (Realtek miniigd), CVE-2016-20016 (MVPower DVR), CVE-2024-3721 (TBK DVR), CVE-2025-34037 (Linksys), CVE-2023-26801 (LB-LINK), CVE-2023-41011 (China Mobile) and CVE-2026-87827 (KGUARD DVR).
What to do

1. Patch or retire
Start with Ivanti. Run a supported Connect Secure or Policy Secure release that includes the January 2024 fixes for CVE-2023-46805 and CVE-2024-21887. If the appliance was exposed and unpatched at any point since then, treat it as possibly compromised and run Ivanti's Integrity Checker Tool.
For routers, cameras and NAS units, match your inventory against the vendor list above and install the vendor's current firmware. D-Link has said it will not fix CVE-2024-10914 or CVE-2024-10915 on the end-of-life DNS-320, DNS-320LW, DNS-325 and DNS-340L, so those units have to be replaced.
2. If you cannot patch today
Make sure no device's web admin page, UPnP service or Telnet is reachable from the internet, and check from outside. Put cameras, DVRs and NAS boxes on their own VLAN and allow outbound traffic only to the hosts they need. A device that cannot reach arbitrary STUN servers or make arbitrary outbound TCP connections is no use as a proxy, even if it is infected.
3. Check whether you were hit
On devices with a shell, run ls -la /root/.cling /usr/local/bin/.cling and grep -n cling /etc/inittab /etc/init.d/rcS /etc/rc.d/rc.boot. Then run grep ' /proc/[0-9]' /proc/mounts: a mount sitting on top of a process directory is the bind-mount trick, and normal systems have none.
On the network, search firewall and NetFlow records for:
- Connections to 124.163.212.119, 222.223.152.97 or 118.145.196.225, the three download hosts.
- Network devices sending small UDP packets to many public STUN servers every few seconds. STUN's registered port is UDP 3478, but neither report gives the ports the bot uses, so match on Fortinet's list of 24 STUN server IPs as well as on port.
- UDP packets claiming to come from 74.125.250.129 with a STUN transaction ID of all zeros, which Nozomi tied to command traffic.
- Outbound TCP sessions from a router or camera to addresses you do not recognise, which is the back-connect proxy at work.
Fortinet's report also lists 21 SHA-256 file hashes and its detection names: BASH/Mirai.AEH!tr.dldr, BASH/Dloader.P!tr and Linux/Agent.BHT!tr.
4. Clean up
Deleting the files by hand is not enough, because you cannot be sure what else the bot changed. Factory reset it, flash current firmware, set a new admin password and patch it before it goes back on the network. For an affected Ivanti appliance, follow Ivanti's guidance to rebuild from a clean image, then reset the local accounts and rotate any certificates and service account passwords it stored.
Watching for STUN traffic
STUN is normal from phones, browsers and video call clients, so few teams look at it. A DVR or NAS has no reason to send it. A flow alert for UDP to known STUN servers from infrastructure VLANs is cheap and would also catch the next family that copies the trick.
Our attack surface management service finds the routers, cameras and VPN gateways you expose to the internet before a scanner like ClingSTUN does, and our network penetration testing checks what an infected device on your network could reach. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: FortiGuard Labs, SecurityWeek, Infosecurity Magazine, Hackread, The Hacker News, Cyber Security News, Ivanti advisory, Tenable, Security Affairs.
Read next
- Rejetto HFS flaw found by AI, exploited within a day
- MagicINFO flaw used to build a Monero miner on the host
- AI agent chains two Zammad zero-days to root at DIVD
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.