On October 5, 2026, FortiGuard Labs published a technical analysis describing ClingSTUN, a Linux backdoor that exploits known vulnerabilities in internet-facing routers and other connected equipment, establishes persistence, and turns infected devices into remotely controlled proxy nodes. The reported behavior can let attackers relay traffic through a compromised device and run commands on it.
What ClingSTUN does
ClingSTUN is a back-connect proxy backdoor: it gives an operator a way to reach an infected device and use it to relay network traffic. FortiGuard’s technical analysis describes three broad parts of the malware’s activity: gaining access through known vulnerabilities, keeping a foothold on the device, and using public Session Traversal Utilities for NAT (STUN) endpoints to support connectivity.
That proxy role matters even when a device is not used to store sensitive information. A compromised router or other connected device can serve as an intermediary for traffic, while the backdoor also provides command-execution capability.
How it gets in and spreads
FortiGuard’s entry-point table lists 24 CVE records. A separate table lists seven hard-coded exploits used for self-propagation; those are distinct categories, not one combined count.
The first delivery FortiGuard identified exploited CVE-2022-36553, a command-injection vulnerability affecting Hytec Inter HWL-2511-SS routers. The report also describes later activity using multiple vulnerabilities, including EnGenius CVE-2025-34035 and D-Link CVE-2024-23625. These are specific examples of listed vulnerabilities and products, not a blanket claim about every device from those manufacturers.
The seven self-propagation CVEs named in the analysis are CVE-2014-8361, CVE-2016-20016, CVE-2024-3721, CVE-2025-34037, CVE-2023-26801, CVE-2023-41011 and CVE-2026-87827. FortiGuard associates them, respectively, with Realtek, MVPower, TBK, Linksys, LB-LINK, China Mobile and KGUARD.
How it persists and hides
FortiGuard reports that ClingSTUN copies itself to /root/.cling and /usr/local/bin/.cling, makes the files executable, and adds startup commands to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot. Those changes are designed to bring the malware back when the device starts.
The analysis also describes the backdoor clearing its original command-line arguments, terminating competing processes and disabling the watchdog timer. When running as root, it can conceal process information by mounting copied PID 1 metadata over its own /proc/<pid> entry.
The downloaders support ARM, Intel 80386, MIPS R3000, PowerPC and AMD x86-64. That range spans several processor architectures used in Linux-based equipment.
Why it uses public STUN services
Network address translation (NAT) lets devices on a private network share an external address. STUN is a standard way for a device to learn the public address and port mapping that a NAT gateway assigns to it. ClingSTUN sends standard 20-byte STUN binding requests over UDP to obtain mapped-address information.
FortiGuard reports that one earlier evolution contacted 24 public STUN endpoints and needed at least half of those connections to succeed. The third evolution contacted 13 endpoints and required every connection to succeed. The malware also periodically sent a group identifier and a list of mapped ports to those endpoints.
The use of a public STUN service alone does not identify that service as attacker-controlled. FortiGuard advises assessing why a device is making the connections, rather than judging the traffic only by the reputation of its destination.
Steps for defenders
Start with an inventory of internet-facing routers and other connected equipment. For each device, track its model, firmware and support status, then apply available updates for the vulnerabilities that match that product. A CVE appearing in a malware report is not by itself a device-by-device exposure assessment.
If a device cannot be patched, FortiGuard recommends reducing its internet exposure, limiting the systems it can communicate with, and monitoring its behavior; equipment that cannot be secured may need to be isolated or replaced. Watch for suspicious processes and recurring STUN or UDP traffic alongside the host indicators and file hashes in FortiGuard’s analysis.
The report lists three defanged host indicators: 124[.]163[.]212[.]119, 222[.]223[.]152[.]97 and 118[.]145[.]196[.]225. Its antivirus detection names are BASH/Mirai.AEH!tr.dldr, BASH/Dloader.P!tr and Linux/Agent.BHT!tr.