Security News

ClingSTUN botnet turns old router, camera and VPN flaws into a proxy network

iTnews · 7 Oct 2026
Key Takeaway Patch or replace internet-facing routers, cameras, recorders and VPN gateways, and retire any device that no longer receives vendor security updates.

Security researchers have detailed ClingSTUN, a Linux botnet that breaks into routers, cameras, video recorders and virtual private network (VPN) gateways using more than 30 known flaws. FortiGuard Labs researcher Vincent Li said the malware turns compromised devices into proxy nodes, letting remote operators route their traffic through them. It also relies on public internet calling infrastructure to keep its foothold reachable.

The targets include two Ivanti Connect Secure and Policy Secure flaws, CVE-2023-46805 and CVE-2024-21887, which attackers chained as zero-days from as early as December 2023. The Australian Cyber Security Centre issued an alert on them in January 2024. Most of the devices listed are consumer and small-business kit from D-Link, TP-Link, Tenda and others, plus digital video recorders. Most of the flaws are command injection bugs, where a web interface passes attacker-supplied text straight to the device's operating system.

Once inside, ClingSTUN removes rival malware, disables the device's hardware watchdog (a timer that reboots a hung device), and adds itself to start-up scripts so it survives restarts. It disguises itself as the system's first trusted program, and infected devices go on to attack others using exploits for seven further flaws, the oldest dating to 2014. Fortinet notes similarities to Mirai, but ClingSTUN acts as a proxy rather than flooding targets with traffic.

Summarised by CISO AI from iTnews, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.