IoT Devices Compromised by New Linux Malware Strain, Used as Proxy Nodes for Malicious Activity
A newly discovered Linux malware strain, dubbed “ClingSTUN” by Fortinet’s FortiGuard Labs researchers, has been found to exploit 24 known vulnerabilities in Internet of Things (IoT) devices, compromising their security and turning them into proxy nodes for malicious activity. This malware is particularly concerning as it uses legitimate public STUN servers to obscure its communication with compromised devices, making it challenging to detect and track.
The ClingSTUN malware targets a wide range of IoT devices, including routers, network equipment, surveillance systems, and industrial systems from manufacturers such as D-Link, Realtek, Ivanti, and TP-Link. The oldest vulnerability exploited by this malware dates back to 2014, while the most recent one was discovered earlier this year. This highlights the growing concern of IoT device vulnerabilities and the need for prompt updates and maintenance.
One of the key features of ClingSTUN is its use of legitimate public STUN servers as a network middleman. The malware periodically sends information about the infected device’s external IP address and reachable ports to these servers, which are then used by attackers to communicate with compromised devices. This approach makes it difficult to distinguish malicious activity from legitimate use, posing significant challenges for security teams.
Once installed, ClingSTUN establishes persistence on the compromised system and includes hard-coded exploits for seven additional vulnerabilities that can be used to spread to other vulnerable IoT systems. The malware’s ability to compromise multiple devices using separate vulnerabilities is a concern, as it allows attackers to create complex attack networks and evade detection.
The use of ClingSTUN by attackers demonstrates how vulnerable IoT devices can become infrastructure for malicious proxy operations. This poses significant risks to enterprises, including IP blocklisting, reputational damage, bandwidth consumption, and operational disruption. Furthermore, compromised devices may provide access to internal destinations they can reach, adding to the threat.
To mitigate this threat, it is essential that organizations maintain an accurate inventory of their IoT devices, reduce unnecessary Internet exposure, and promptly update firmware and software. Monitoring outbound communications from these devices is also crucial in detecting potential malicious activity. While blocking public STUN servers may seem like a solution, FortiGuard analyst Vincent Li cautions against indiscriminate blocking, as this can disrupt legitimate applications and devices that rely on STUN servers.
As the use of IoT devices continues to grow, so does the risk of cyber threats targeting these devices. The discovery of ClingSTUN highlights the importance of prioritizing IoT security and taking proactive measures to prevent vulnerabilities from being exploited. By staying vigilant and adapting our defenses to address emerging threats, we can reduce the risks associated with IoT device compromise and protect both our networks and reputations.
Source: Dark Reading — 2026-10-05