ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote access.

Rather than simply infecting routers and cameras, it turns compromised equipment into remotely controlled proxy nodes that can relay traffic and run commands. The campaign targets known security flaws across multiple vendors, expanding its attack methods as it evolves.

Unpatched firmware, unsupported hardware, and exposed services create openings for infections that can survive device restarts and conceal their activity from routine checks. Fortinet researchers identified three stages of the campaign, each using a different download source.

Fortinet said in a report shared with Cyber Security News (CSN) that ClingSTUN combines vulnerability exploitation, startup persistence, and public networking services to maintain access to infected Linux devices.

The October 5 analysis describes a high-severity threat but does not provide an infection count or confirmed victim list.

Its findings show how ordinary connected equipment can become persistent attack infrastructure, with consequences extending beyond the device originally compromised.

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities

Researchers first observed delivery through CVE-2022-36553, a command injection flaw in Hytec Inter HWL-2511-SS routers.

That initial stage lasted only two days before the attackers changed download infrastructure and broadened their exploitation strategy to reach additional vulnerable products.

The second stage targeted the EnGenius cloud service vulnerability CVE-2025-34035 and D-Link UPnP flaw CVE-2024-23625. Later activity added Realtek, Linear, TP-Link, AVTECH, and other devices, showing that the operators were not relying on one manufacturer or a single entry point.

The second-evolution downloader script, ‘wget.sh’ (Source – Fortinet)

Among those targets was CVE-2023-1389 in TP-Link Archer AX21 routers. Earlier reporting on TP-Link command injection attacks documented exploitation of the same weakness, illustrating how familiar vulnerabilities remain useful to attackers when exposed devices stay unpatched.

The campaign also exploited CVE-2024-7029 in AVTECH AVM1203 cameras, a weakness previously associated with Mirai attacks against cameras in another campaign. The overlap concerns reused vulnerabilities, not evidence that ClingSTUN belongs to the same malware family or shares those operators.

Downloaders retrieve versions for ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64 systems. The newest downloader also removes certain process-related mounts and terminates processes running from temporary storage, helping clear competing activity before the backdoor establishes itself.

ClingSTUN then creates hidden executable copies and modifies three startup files so it runs during boot. It also disables watchdog timers and kills selected processes, combining persistence with interference against programs that could compete with it on the infected device.

Public STUN Services Conceal Connectivity

ClingSTUN clears its command-line arguments to make ordinary process listings less informative. When running with administrator privileges, it overlays its process information with metadata copied from the system’s initial process.

Similar Linux malware process concealment techniques highlight why appearance alone cannot establish whether a process is legitimate.

The backdoor uses STUN, a protocol commonly involved in internet calls and browser communications, to discover external address and port mappings.

The analyzed second version contacted 24 public endpoints; the third reduced that number to 13 and required successful connections to every endpoint. A 20-byte operator packet can activate remote command execution or self-propagation.

One command directs an outbound TCP connection to a specified endpoint, where the malware receives instructions to execute. Researchers identified seven built-in vulnerability exploits supporting further spread to routers and recording equipment.

Killing competitor processes (Source - Fortinet)
Killing competitor processes (Source – Fortinet)

However, researchers could not verify how operators obtain the external mappings and deliver control traffic through network address translation. Public STUN servers should not automatically be treated as malicious infrastructure.

Defenders should instead correlate these connections with suspicious processes, unexpected UDP activity, and recurring keepalive traffic.

Fortinet recommends inventorying internet-facing devices, tracking firmware support, and promptly patching actively exploited vulnerabilities.

Unsupported equipment should be replaced or isolated, while unnecessary exposed services should be restricted. Monitoring startup changes alongside unusual network behavior helps identify devices that have become persistent backdoors.

The indicators below reproduce campaign hosts, hashes, and observed artifacts from the source. Public STUN endpoints provide investigative context and are not confirmed attacker-controlled infrastructure.

Indicators of compromise (IoCs):-

Type Indicator Description
Campaign IPv4 124[.]163[.]212[.]119 First-stage malware delivery host.
Campaign IPv4 222[.]223[.]152[.]97 Second-stage malware download host.
Campaign IPv4 118[.]145[.]196[.]225 Third-stage malware download host.
SHA-256 dc892f5013edb0aa1e61e808511387373d8d120348b5be0929621d21e6e9946a File hash listed in the source’s campaign IoCs.
SHA-256 a297eddfa7abea8d411afc0f150f8f6f30e470a77204de87e3b0815fa9bb8a84 File hash listed in the source’s campaign IoCs.
SHA-256 4fbd61cb9181ebbc4fe9a6e59d3c346dc00001da48d66bd890556fc6fad22b07 File hash listed in the source’s campaign IoCs.
SHA-256 121f2050e3c891b29565fd73451fff7ae60199c86eb8d79ec1eb1d9844578487 File hash listed in the source’s campaign IoCs.
SHA-256 48f9b72ce72ab7087794650d6eef10135345088384fbde1482f1c74a02b80302 File hash listed in the source’s campaign IoCs.
SHA-256 e6e113783356446aef66e5296db45b244f318292af7cebc2a9bd76f095a95c4c File hash listed in the source’s campaign IoCs.
SHA-256 c1d8e2829ea63b9dc1cf2c3421a5093406adad4d6622e238376e78e908e0e6e8 File hash listed in the source’s campaign IoCs.
SHA-256 48962b3893f2c8261e32e6b95ea7d463d145a529a8b2a6c987dd979454405c73 File hash listed in the source’s campaign IoCs.
SHA-256 76692a23abe718b93e63edefd743971ec627c0cdf3778f856bd5ec88003deaa2 File hash listed in the source’s campaign IoCs.
SHA-256 ec199c78c11040fd3127887222fd75a85e5797bf96aa691a117fdd83dd663d81 File hash listed in the source’s campaign IoCs.
SHA-256 c0d8ffebfba969b1c1ca76bd9623bb623e9f95155c8ceca77d8fcc521435a497 File hash listed in the source’s campaign IoCs.
SHA-256 f49f45303cbfccee14ff193ac9608f860e6d616f08c0ecbef1ec44f7c863d7ec File hash listed in the source’s campaign IoCs.
SHA-256 9391c6ad17aced1142607c0c623b18d86a7697cc483d204ffac94093e26b8068 File hash listed twice in the source; reproduced once here.
SHA-256 e4d12208789f36efc5a1ff765088fed95d6bb5972d1a804a4536fd42366797d4 File hash listed in the source’s campaign IoCs.
SHA-256 284e5ec8748f99fd1b8c331b699a5fe5fd4448bbaae0347a940f427f931c4d14 File hash listed in the source’s campaign IoCs.
SHA-256 6581bf37184bb2db899b9893064d39dd314ea691adf3281cc0aa7e0a31e5138a File hash listed in the source’s campaign IoCs.
SHA-256 10d83c1748895361e07320f68d44d427b43cadd2cbffe0ab5e607ab03aec83da File hash listed in the source’s campaign IoCs.
SHA-256 2ed54e0f988a62039abed88f6394eb1e3d5ed931f0183556055417fb08844ecf File hash listed in the source’s campaign IoCs.
SHA-256 b90640b392827b4f2d280f6cf67860862953331917d42df23e1653a92f2f98ad File hash listed in the source’s campaign IoCs.
SHA-256 dfba6008a2c828a9cb62342aec53006ae05a60cb8d4c41c3fa216fd727e8c6a3 File hash listed in the source’s campaign IoCs.
SHA-256 5c4e263546fb21f8fe8732789a5b6583eaa8ae11ebeef099462a7c9bf50e022d File hash listed in the source’s campaign IoCs.
File name wget.sh Downloader script identified in the second and third stages.
File name m.x86_64 Analyzed second-stage AMD x86-64 malware executable.
File name x86_64 Analyzed third-stage AMD x86-64 malware executable.
Malware path /root/.cling Hidden executable copy created for persistence.
Malware path /usr/local/bin/.cling Additional hidden executable copy created for persistence.
Persistence target /etc/inittab Legitimate startup file modified to launch the malware.
Persistence target /etc/init.d/rcS Legitimate startup script modified for boot execution.
Persistence target /etc/rc.d/rc.boot Legitimate boot file modified for persistence.
Behavioral context /tmp Download, execution, process-termination, and concealment location; not a standalone IoC.
Behavioral context /var/tmp Directory checked when selecting processes for termination; not a standalone IoC.
Behavioral context /proc/mounts Mount information examined by the third-stage downloader.
Behavioral context /proc Process information directory enumerated by the malware.
Behavioral context /proc/<pid>/cmdline Process command-line information checked during process termination.
Behavioral context /proc/<pid>/exe Executable reference inspected during process termination.
Behavioral context /proc/1/ Source of legitimate process metadata copied for concealment.
Behavioral context /proc/<pid> Malware process directory overlaid to conceal its information.
Behavioral context /dev/watchdog Legitimate watchdog interface manipulated by the malware.
Behavioral context /dev/misc/watchdog Additional legitimate watchdog interface manipulated by the malware.
Exploit target file card_scan_decoder.php Linear eMerge entry point; not a standalone compromise indicator.
Exploit target file popen.cgi Hytec router entry point; not a standalone compromise indicator.
Exploit target file Factory.cgi AVTECH camera entry point; not a standalone compromise indicator.
Exploit target file account_mgr.cgi D-Link entry point; not a standalone compromise indicator.
Exploit target component luci.stok TP-Link Archer AX21 entry point identified in the source.
Exploit target component hnap_main D-Link Go-RT-AC750 component targeted through a buffer overflow.
Public STUN IPv4 5[.]39[.]72[.]109 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 77[.]72[.]169[.]213 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 154[.]73[.]34[.]8 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 20[.]14[.]234[.]56 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 81[.]187[.]30[.]115 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 185[.]125[.]180[.]70 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 64[.]131[.]63[.]217 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 82[.]113[.]193[.]63 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 207[.]38[.]82[.]134 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 66[.]51[.]128[.]1 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 83[.]211[.]9[.]232 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 212[.]53[.]40[.]43 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 74[.]125[.]250[.]129 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 85[.]17[.]88[.]164 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 212[.]227[.]67[.]33 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 77[.]72[.]169[.]210 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 85[.]93[.]219[.]114 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 212[.]227[.]67[.]34 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 77[.]72[.]169[.]211 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 139[.]162[.]62[.]29 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 216[.]93[.]246[.]18 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 77[.]72[.]169[.]212 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 145[.]249[.]115[.]184 Contacted public endpoint; not confirmed attacker-controlled.
Public STUN IPv4 217[.]0[.]0[.]249 Contacted public endpoint; not confirmed attacker-controlled.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access appeared first on Cyber Security News.