Threat Intelligence

ClingSTUN Backdoor Hijacks Vulnerable IoT Devices to Use as Proxy Nodes

Dark Reading · 6 Oct 2026
Key Takeaway Make a list of every internet-connected device in your business and apply available firmware updates, replacing any that no longer receive security patches.

Researchers have identified a Linux backdoor called ClingSTUN that targets internet-connected (IoT) devices and turns them into proxy nodes. According to the report, it spreads by exploiting 24 known vulnerabilities, meaning the flaws it relies on already have public details and are not new zero-day weaknesses.

To obscure its communications, ClingSTUN uses legitimate public STUN servers. Because these servers are real, widely used services, the traffic it generates may be harder to distinguish from normal activity.

For small businesses, the lesson is that everyday devices such as cameras, routers and other smart equipment can be taken over and used by attackers if they are left unpatched. Since the flaws involved are already known, keeping device software current is a direct way to reduce exposure.

ClingSTUN IoT security Linux malware backdoor patch management

Summarised by CISO AI from Dark Reading, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.