Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

ClingSTUN Linux backdoor hides in STUN traffic, exploiting 30+ IoT and router flaws, Fortinet says

The malware blends its traffic with ordinary video-call connections and turns unpatched routers, cameras and recorders into remotely controlled relay points.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Fortinet's FortiGuard Labs said on October 5 that ClingSTUN exploits more than 30 vulnerabilities in internet-facing devices.
  • 2The backdoor contacts legitimate public STUN servers so its traffic resembles normal video-call and VoIP connections.
  • 3Nozomi Networks saw a spike in exploit attempts against a 2021 Realtek SDK flaw starting around September 5.

The news

Fortinet (FTNT) researchers have detailed the ClingSTUN Linux backdoor, malware that turns unpatched routers, cameras and other internet-facing devices into proxy nodes that attackers control remotely. In a FortiGuard Labs blog post published on October 5, 2026, researcher Vincent Li said it exploits more than 30 distinct vulnerabilities to get in.

The unusual part is how it stays connected. STUN (Session Traversal Utilities for NAT) is a standard protocol that video-calling and WebRTC apps use to learn a device's public internet address. According to Fortinet, ClingSTUN sends standard STUN requests to legitimate public STUN servers, 24 in earlier versions and 13 in later ones, so it can keep working behind home and office routers. That traffic can blend in with normal VoIP and WebRTC communications, the researchers said.

Fortinet describes ClingSTUN as a back-connect proxy backdoor: a compromised device reaches out to the attackers, who can then run commands on it and route traffic through it. The malware carries seven hard-coded exploits to spread itself, disguises its process as a core system process, kills rival malware and sets itself to restart on boot, according to the post. It runs on several chip architectures, including ARM, MIPS, PowerPC and x86.

The targets span many brands. Fortinet named devices from EnGenius, D-Link, Linear, Realtek, TP-Link and AVTECH, among others, with example flaws including CVE-2025-34035 in EnGenius products and CVE-2024-23625 in D-Link's UPnP service. SecurityWeek, which reviewed the research, listed further vendors such as Ivanti, Lantronix, Tenda, Linksys and MVPower, and said Fortinet did not attribute the campaign to any group, describing the exploitation as indiscriminate.

Other researchers have seen the same activity from a different angle. The Hacker News reported that Nozomi Networks, an operational technology security company, detected a spike in exploit attempts starting around September 5 against CVE-2021-35394, a critical remote code execution flaw rated 9.8 in Realtek's Jungle software development kit used in many routers. The outlet said the malware, which Nozomi calls Cling, results in a botnet whose traffic can resemble legitimate NAT traversal while supporting proxying, tunneling and denial-of-service commands.

The numbers

Distinct vulnerabilities exploited (Fortinet)
30+
Hard-coded exploits for self-spreading (Fortinet)
7
Public STUN servers contacted, later versions (Fortinet)
13
CVSS score of Realtek flaw CVE-2021-35394
9.8

Why CEOs should care

For CISOs and network teams, the main risk is that your own devices become someone else's attack infrastructure. A hijacked branch router or security camera relaying criminal traffic can get your IP addresses blocked, draw law enforcement inquiries, and give attackers a foothold near internal networks. Ask: do we have a current inventory of every internet-facing router, camera, DVR and gateway, including those at branches and franchise sites, and which are past end of support?

Detection teams should take Fortinet's warning seriously: public STUN servers are not malicious in themselves, so blocking them outright can break video calls. Fortinet advises assessing STUN activity alongside suspicious process behavior. A practical question for your monitoring provider is whether it can flag STUN or unexpected UDP traffic from devices that should never be making video calls, such as DVRs and building controllers.

For CFOs and boards, the fix is mostly unglamorous spending: replacing unsupported devices, disabling internet-facing services nobody uses, and paying for patching at remote sites. One of the exploited flaws dates to 2021, a sign that old, unpatched equipment remains the easiest way in.

The bigger picture

Attackers increasingly build proxy networks from compromised home and small-office devices, because traffic coming from ordinary residential and business addresses is hard to block. ClingSTUN adds a twist by borrowing legitimate public infrastructure for coordination instead of relying only on servers the attackers run, which makes simple blocklists less useful.

What’s next

Watch for device makers to confirm which products remain unpatched, for security vendors to publish detection rules for ClingSTUN, and for any reports of the proxy network being used in specific attacks.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

FortinetClingSTUNNozomi NetworksIoT securityBotnets

Earlier coverage of Fortinet

All Fortinet coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.