Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ClingSTUN Backdoor Targets IoT Devices for Remote Access

ClingSTUN Backdoor Targets IoT Devices for Remote Access

Posted on October 6, 2026 By CWS

ClingSTUN is a malicious Linux software that takes advantage of weaknesses in internet-connected devices, providing attackers with continual remote access. This sophisticated backdoor not only infects devices like routers and cameras but also transforms them into proxy nodes that can reroute traffic and execute commands remotely. The operation exploits known vulnerabilities in various vendor products, adapting its tactics as it progresses.

Exploiting IoT Device Vulnerabilities

Unpatched firmware, unsupported hardware, and exposed services are some of the vulnerabilities that ClingSTUN exploits to ensure infections persist through device reboots and evade detection. Researchers from Fortinet have identified three stages of this campaign, each utilizing distinct download sources to propagate the malware.

According to a report shared with Cyber Security News, the ClingSTUN operation involves exploiting vulnerabilities, ensuring startup persistence, and using public networking services to maintain control over compromised Linux devices. Although the threat is severe, the exact number of infections or a list of confirmed victims remains unreported.

Stages of the ClingSTUN Campaign

The initial stage of the campaign was detected using CVE-2022-36553, a command injection flaw in Hytec Inter HWL-2511-SS routers. This phase lasted only two days before the attackers diversified their methods and extended their reach to other vulnerable devices.

The second phase involved exploiting vulnerabilities in EnGenius cloud services and D-Link’s UPnP, among others. As the campaign evolved, more devices from manufacturers like Realtek, TP-Link, and AVTECH became targets, demonstrating the attackers’ strategy to leverage multiple entry points.

ClingSTUN’s downloader scripts are capable of supporting various systems, including ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64. The malware also removes certain process-related mounts and kills processes from temporary storage to establish its presence without interference.

Concealment and Persistence Techniques

ClingSTUN employs several techniques to conceal its operations. It clears command-line arguments, making it difficult to identify through standard process listings. When executed with admin privileges, it overlays its information with system metadata, mimicking legitimate processes.

The malware utilizes the STUN protocol, commonly used in internet calls, to discover external address mappings. The latest version contacted fewer public endpoints, requiring successful connections to each for remote command execution or self-propagation. The backdoor can also execute outbound TCP connections to receive further instructions.

Despite its capabilities, researchers have yet to determine how operators manage to obtain external mappings and deliver control traffic through network address translation. Public STUN servers should not be automatically deemed malicious but should be correlated with other suspicious activities.

Security Recommendations

Fortinet advises organizations to inventory internet-facing devices, ensure firmware is up-to-date, and promptly address exploited vulnerabilities. Unsupported devices should be replaced or isolated, and unnecessary services should be restricted. Monitoring for startup changes and unusual network behavior can help detect devices that have become persistent backdoors.

Indicators of compromise include specific campaign hosts, file hashes, and observed artifacts. Although these provide context for investigations, they are not confirmed as attacker-controlled infrastructure. Vigilance and proactive measures remain key in mitigating such sophisticated threats.

Cyber Security News Tags:ClingSTUN, Cybersecurity, Fortinet, internet-connected devices, IoT security, Linux backdoor, Malware, network security, remote access, Vulnerabilities

Post navigation

Previous Post: Apple Strengthens macOS Disk Access Amid AI Concerns
Next Post: Wikimedia Discovers Unauthorized OpenAI Bot Activities

Related Posts

Ubiquiti Releases Critical Updates for UniFi OS Vulnerabilities Ubiquiti Releases Critical Updates for UniFi OS Vulnerabilities Cyber Security News
North Korean Hackers Weaponizing NPM Packages to Steal Cryptocurrency and Sensitive Data North Korean Hackers Weaponizing NPM Packages to Steal Cryptocurrency and Sensitive Data Cyber Security News
Microsoft Teams Enhances Security with Bot Blocking Microsoft Teams Enhances Security with Bot Blocking Cyber Security News
Kaspersky Security Zero-Day Claims Raise Concerns Kaspersky Security Zero-Day Claims Raise Concerns Cyber Security News
Malicious Joyfill npm Packages Compromise Developer Security Malicious Joyfill npm Packages Compromise Developer Security Cyber Security News
Russian Hacking Groups Gamaredon and Turla Attacking Organizations to Deploy Kazuar Backdoor Russian Hacking Groups Gamaredon and Turla Attacking Organizations to Deploy Kazuar Backdoor Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FBI Captures Developer Behind Notorious ATM Malware
  • Wikimedia Discovers Unauthorized OpenAI Bot Activities
  • ClingSTUN Backdoor Targets IoT Devices for Remote Access
  • Apple Strengthens macOS Disk Access Amid AI Concerns
  • Security Flaws in LibreOffice and OpenOffice Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FBI Captures Developer Behind Notorious ATM Malware
  • Wikimedia Discovers Unauthorized OpenAI Bot Activities
  • ClingSTUN Backdoor Targets IoT Devices for Remote Access
  • Apple Strengthens macOS Disk Access Amid AI Concerns
  • Security Flaws in LibreOffice and OpenOffice Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark