ClingSTUN Linux Backdoor Hides in Public STUN Traffic

ClingSTUN Linux backdoor hiding command traffic in public STUN servers to turn routers into a STUN abuse malware proxy network

A Backdoor That Blends Into Calls and Video

The ClingSTUN Linux backdoor has learned to hide its command activity where network defenses expect ordinary calls and video chats. The malware uses public STUN servers. As a result, its UDP traffic blends with legitimate VoIP and WebRTC streams.

How ClingSTUN Abuses STUN

STUN helps a device behind NAT learn its external IP address and mapped port. ClingSTUN uses the same mechanism to keep UDP connections reachable from outside.

In this way, it turns infected Linux devices into remotely controlled proxy nodes. One studied version contacted 24 public STUN endpoints. A newer one cut the list to 13.

Old Flaws Open the Door

To infect devices, the operators exploit known holes in internet-facing equipment. The first attacks used CVE-2022-36553 in Hytec routers.

Later, the chain added CVE-2025-34035 in EnGenius gear and CVE-2024-23625 in D-Link devices. ClingSTUN also spread through the TP-Link Archer AX21, which carries CVE-2023-1389.

Persistence and Stealth

Once inside, the backdoor copies itself into hidden files and sets itself to run at boot. It also kills rival processes and tampers with the watchdog.

With root rights, ClingSTUN disguises its process details as those of PID 1. The FortiGuard Labs analysis also describes builds for ARM, x86, MIPS, PowerPC, and x86-64.

Built to Spread

ClingSTUN carries exploits for seven vulnerabilities. It uses them to spread further.

How to Detect It

Fortinet advises against flagging STUN traffic on its own. Public STUN servers remain legitimate infrastructure. Instead, defenders should correlate such traffic with unexpected UDP connections, constant keepalive packets, and suspicious processes.

Meanwhile, the main entry point remains the same: long-unpatched devices exposed directly to the internet.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply