On Oct. 5, 2026, FortiGuard Labs published an analysis of ClingSTUN, a Linux back-connect proxy backdoor that uses public STUN services to discover external IP addresses and port mappings. FortiGuard says the malware can persist on compromised devices, interfere with system processes and execute remote commands, allowing those devices to act as proxy nodes.

ClingSTUN is a reported Linux proxy backdoor

ClingSTUN is designed to maintain access to a compromised Linux device and make it available as a remotely controlled proxy node. FortiGuard describes three campaign periods with changing download sources; it does not attach calendar dates to those periods.

The campaign’s reach into exposed devices involved two separate exploit sets. FortiGuard associates 24 vulnerabilities with initial access and lists seven hard-coded exploits that ClingSTUN uses for self-propagation. The counts describe different roles: one set is tied to gaining initial access, while the other is built into the malware to help it spread.

Why ClingSTUN contacts public STUN services

STUN, short for Session Traversal Utilities for NAT, helps a device discover the public-facing IP address and port mapping created by a network address translator (NAT). FortiGuard says ClingSTUN sends standard 20-byte STUN binding requests over UDP to learn those external mappings. The services it contacts are legitimate public STUN endpoints.

The malware’s STUN behavior has changed across the versions FortiGuard describes. An earlier implementation contacted 24 public endpoints and needed at least half to respond successfully. A later evolution contacted 13 endpoints and required all 13 to succeed. Afterward, ClingSTUN periodically sent a group identifier and mapped-port list to those same endpoints.

FortiGuard says the exact way operators use the mappings to deliver control traffic through NAT remains unverified. The STUN exchanges describe the discovery of network mappings; the subsequent control mechanism is a separate part of the picture.

Initial access and self-propagation use different exploits

FortiGuard lists 24 CVEs associated with campaign initial access across internet-facing routers, IoT and cloud services, network equipment and other devices. Separately, its analysis lists seven hard-coded propagation exploits associated with Realtek, MVPower, TBK, Linksys, LB-LINK, China Mobile and KGUARD devices or services.

That distinction matters when interpreting the counts: the seven propagation exploits are not additional entries in the 24-CVE initial-access list. FortiGuard also describes payloads for ARM, Intel 80386, MIPS R3000, PowerPC and AMD x86-64 architectures.

Persistence, process interference and remote commands

FortiGuard says ClingSTUN copies itself to /root/.cling and /usr/local/bin/.cling, then appends startup commands to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot. Those changes are intended to help the malware start again when the system boots.

The reported behavior also includes killing selected processes and interfering with watchdog timers, which monitor whether a device is operating normally. When running as root, ClingSTUN can conceal process information by bind-mounting copied PID 1 process information over its own process directory.

FortiGuard describes a remote-command routine in which a control packet can trigger an outbound TCP connection to a specified endpoint. The malware receives a command through that connection and executes it.

What defenders can look for

FortiGuard recommends assessing STUN activity in the context of each device’s role, alongside suspicious processes, unexpected UDP communications and recurring keepalive traffic. It also describes a group identifier and mapped-port list in recurring messages as behavioral clues.

For network teams, the practical response is to inventory internet-facing equipment, apply available updates and limit unnecessary exposure. Blocking public STUN traffic indiscriminately can disrupt legitimate services, so the traffic needs to be considered alongside the device’s other behavior.