A New Threat Erupts: ClingSTUN Turns Vulnerable IoT Devices into Proxy Nodes, Exposing Enterprises to Malicious Activity
Researchers have uncovered a sophisticated new malware strain, dubbed “ClingSTUN,” that is turning vulnerable Internet of Things (IoT) devices into proxy nodes for malicious activity. This malware exploits 24 known flaws in a wide range of IoT devices, including routers, network equipment, surveillance systems, and industrial systems from manufacturers such as D-Link, Realtek, Ivanti, and TP-Link. The use of legitimate public STUN servers to obscure communications makes ClingSTUN particularly noteworthy.
The malware’s persistence mechanism allows it to establish a foothold on compromised devices, while its hard-coded exploits for seven additional vulnerabilities enable it to spread to other vulnerable IoT systems. This creates significant risks for enterprises, as compromised devices can serve as intermediaries through which attackers can route traffic, making malicious activity appear to originate from the enterprise’s public IP address.
The use of STUN servers by ClingSTUN makes its activity difficult to distinguish from legitimate use by applications and devices that need to discover their external network mappings. This means that indiscriminately blocking public STUN servers is not a viable solution for mitigating the threat. Instead, enterprises should focus on maintaining an accurate device inventory, reducing unnecessary Internet exposure, and promptly updating firmware and software.
Fortinet’s FortiGuard Labs researchers identified ClingSTUN after tracking attacks targeting at least 24 known vulnerabilities in IoT devices. The oldest of these vulnerabilities is a long-patched command injection vulnerability from 2021 (CVE-2021-36380) in Sunhillo SureLine surveillance data distribution software used by the FAA and other aviation authorities. The most recent is a command injection flaw from earlier this year (CVE-2026-36356) that affects MeiG Smart FORGE_SLT711 devices.
The malware’s use of legitimate public STUN servers to maintain connectivity with compromised devices allows attackers to obscure their infrastructure in otherwise legitimate Internet traffic. According to FortiGuard analyst Vincent Li, the attackers are deploying ClingSTUN in multiple attack waves using a rapidly expanding list of vulnerabilities to gain access to exposed devices.
ClingSTUN’s use of STUN servers is a clever tactic that makes its activity difficult to detect. The malware periodically sends information about the infected device back to the STUN servers, which can then be used by attackers to communicate with compromised devices. However, FortiGuard has not found any evidence of a traditional command-and-control server involved in this process.
The presence of ClingSTUN on an enterprise network can have severe consequences, including IP blocklisting, reputational damage, bandwidth consumption, and operational disruption. Enterprises should take immediate action to mitigate the threat by implementing robust security measures, such as monitoring outbound communications from IoT devices and maintaining up-to-date firmware and software.
In conclusion, ClingSTUN is a sophisticated malware strain that highlights the growing risks associated with vulnerable IoT devices. By understanding how this malware works and taking proactive steps to secure their networks, enterprises can protect themselves against malicious activity and prevent damage to their reputation and operations.
Source: Dark Reading — 2026-10-05