Security News

ClingSTUN Malware Hijacks Unpatched Routers and Cameras to Run Hidden Proxy Networks

Infosecurity Magazine · 6 Oct 2026
Key Takeaway Patch or replace internet-facing routers, cameras and other IoT devices as soon as fixes exist, and isolate any that cannot be updated from your main business systems.

A Linux backdoor named ClingSTUN is turning vulnerable internet-connected devices into remotely controlled proxy nodes, according to research published on October 5 by FortiGuard Labs. The malware exploits known flaws that have not been patched. FortiGuard tracked the campaign across three periods, each using a different download server. It began with a single flaw in Hytec Inter routers, then widened to devices from EnGenius, D-Link, Linear, Realtek, TP-Link and AVTECH. FortiGuard's list now stands at 24 vulnerabilities, including Ivanti Connect Secure flaws.

Once inside, ClingSTUN contacts public STUN servers, which are legitimate services normally used for VoIP and WebRTC. This lets it discover its external address and keep a path open to the device, so the traffic looks like ordinary calling activity. FortiGuard said how the operator pushes commands through is unverified, and warned against treating the STUN services themselves as attacker-controlled. The malware also kills competing processes, copies itself into system locations, edits boot scripts to survive restarts, and disguises itself as a system process. It supports remote command execution and carries built-in exploits for seven more vulnerabilities to spread.

Louis Eichenbaum of ColorTokens said organisations cannot patch their way out of cyber risk, and argued for extra controls around devices that cannot be fixed immediately, including microsegmentation. John Gallagher of Viakoo disagreed on segmentation.

Summarised by CISO AI from Infosecurity Magazine, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.