Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ClingSTUN Backdoor Targets IoT Devices for Remote Access

ClingSTUN Backdoor Targets IoT Devices for Remote Access

Posted on October 6, 2026 By CWS

ClingSTUN is a malicious Linux software that takes advantage of weaknesses in internet-connected devices, providing attackers with continual remote access. This sophisticated backdoor not only infects devices like routers and cameras but also transforms them into proxy nodes that can reroute traffic and execute commands remotely. The operation exploits known vulnerabilities in various vendor products, adapting its tactics as it progresses.

Exploiting IoT Device Vulnerabilities

Unpatched firmware, unsupported hardware, and exposed services are some of the vulnerabilities that ClingSTUN exploits to ensure infections persist through device reboots and evade detection. Researchers from Fortinet have identified three stages of this campaign, each utilizing distinct download sources to propagate the malware.

According to a report shared with Cyber Security News, the ClingSTUN operation involves exploiting vulnerabilities, ensuring startup persistence, and using public networking services to maintain control over compromised Linux devices. Although the threat is severe, the exact number of infections or a list of confirmed victims remains unreported.

Stages of the ClingSTUN Campaign

The initial stage of the campaign was detected using CVE-2022-36553, a command injection flaw in Hytec Inter HWL-2511-SS routers. This phase lasted only two days before the attackers diversified their methods and extended their reach to other vulnerable devices.

The second phase involved exploiting vulnerabilities in EnGenius cloud services and D-Link’s UPnP, among others. As the campaign evolved, more devices from manufacturers like Realtek, TP-Link, and AVTECH became targets, demonstrating the attackers’ strategy to leverage multiple entry points.

ClingSTUN’s downloader scripts are capable of supporting various systems, including ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64. The malware also removes certain process-related mounts and kills processes from temporary storage to establish its presence without interference.

Concealment and Persistence Techniques

ClingSTUN employs several techniques to conceal its operations. It clears command-line arguments, making it difficult to identify through standard process listings. When executed with admin privileges, it overlays its information with system metadata, mimicking legitimate processes.

The malware utilizes the STUN protocol, commonly used in internet calls, to discover external address mappings. The latest version contacted fewer public endpoints, requiring successful connections to each for remote command execution or self-propagation. The backdoor can also execute outbound TCP connections to receive further instructions.

Despite its capabilities, researchers have yet to determine how operators manage to obtain external mappings and deliver control traffic through network address translation. Public STUN servers should not be automatically deemed malicious but should be correlated with other suspicious activities.

Security Recommendations

Fortinet advises organizations to inventory internet-facing devices, ensure firmware is up-to-date, and promptly address exploited vulnerabilities. Unsupported devices should be replaced or isolated, and unnecessary services should be restricted. Monitoring for startup changes and unusual network behavior can help detect devices that have become persistent backdoors.

Indicators of compromise include specific campaign hosts, file hashes, and observed artifacts. Although these provide context for investigations, they are not confirmed as attacker-controlled infrastructure. Vigilance and proactive measures remain key in mitigating such sophisticated threats.

Cyber Security News Tags:ClingSTUN, Cybersecurity, Fortinet, internet-connected devices, IoT security, Linux backdoor, Malware, network security, remote access, Vulnerabilities

Post navigation

Previous Post: Apple Strengthens macOS Disk Access Amid AI Concerns
Next Post: Wikimedia Discovers Unauthorized OpenAI Bot Activities

Related Posts

GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities Cyber Security News
Docker Open Sources Production-Ready Hardened Images for Free Docker Open Sources Production-Ready Hardened Images for Free Cyber Security News
Securing the Cloud Best Practices for Multi-Cloud Environments Securing the Cloud Best Practices for Multi-Cloud Environments Cyber Security News
Next.js Addresses Critical Security Vulnerabilities Next.js Addresses Critical Security Vulnerabilities Cyber Security News
Bing Search Leads to Akira Ransomware Attack via SEO Poisoning Bing Search Leads to Akira Ransomware Attack via SEO Poisoning Cyber Security News
Cyber Attack via Prayer App Amid US-Israel Strikes on Iran Cyber Attack via Prayer App Amid US-Israel Strikes on Iran Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FBI Dismisses Contractor After Security Lapse
  • FBI Captures Developer Behind Notorious ATM Malware
  • Wikimedia Discovers Unauthorized OpenAI Bot Activities
  • ClingSTUN Backdoor Targets IoT Devices for Remote Access
  • Apple Strengthens macOS Disk Access Amid AI Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FBI Dismisses Contractor After Security Lapse
  • FBI Captures Developer Behind Notorious ATM Malware
  • Wikimedia Discovers Unauthorized OpenAI Bot Activities
  • ClingSTUN Backdoor Targets IoT Devices for Remote Access
  • Apple Strengthens macOS Disk Access Amid AI Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark