ClingSTUN: The Linux Backdoor Hiding in Your Router's Traffic

A newly tracked malware strain is quietly turning home routers, security cameras, and smart-office hardware into a criminal relay network, and it uses the internet's own plumbing to avoid detection.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 4 min read
Illustration: a cluster of small consumer networking devices, routers and cameras with blinking LED lights
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Fortinet's FortiGuard Labs has been tracking a Linux malware strain called ClingSTUN that turns infected internet-facing devices into remotely controlled relay points for criminal traffic.
  • ClingSTUN abuses public STUN servers, which are legitimate networking services used by video calls and voice-over-IP apps, to blend its communications into normal traffic and avoid blocklists.
  • Confirmed targets include Hytec routers, EnGenius IoT devices, D-Link hardware, TP-Link Archer AX21 routers, and AVTECH cameras.
  • The malware supports five processor architectures, letting a single operation hit a broad pool of cheap embedded hardware at once.
  • Fortinet's advisory ties the campaign directly to delayed patching, unsupported firmware, and devices left unnecessarily exposed to the internet.

Your router probably isn't storing anything a criminal would want to steal. ClingSTUN's designers already knew that, and they didn't care.

FortiGuard Labs, the research arm of network-security company Fortinet, has spent months tracking a Linux malware strain called ClingSTUN that targets the kind of hardware most people forget exists: home and small-business routers, DVRs, and internet-connected cameras. Linux, here, refers to the operating system that runs silently on most of that hardware. The malware doesn't steal files. It turns the device into a relay point, a quiet tunnel that criminals can push traffic through or use to run commands on other targets. That's the same basic playbook we covered on 15 August when Evooo1Bot was hijacking gateway devices to sell as proxies, and it keeps working because the underlying problem hasn't changed.

How does it actually hide?

ClingSTUN's main trick is abusing STUN, which stands for Session Traversal Utilities for NAT. STUN is a perfectly ordinary internet service that apps like Zoom or WhatsApp use to figure out a device's public address and punch through the network hardware sitting between your device and the wider internet. ClingSTUN contacts the same legitimate public STUN servers those apps use, sending check-in messages disguised as standard video-call traffic.

Because the destinations look normal, reputation-based security filters, which check whether a server is known to be malicious, don't flag the connections. Jason Soroko, senior fellow at Sectigo, told CSO Online: "Security teams should investigate why a device is making those connections, rather than assume the service it contacts is malicious or compromised." Behavior matters more than destination.

Once inside, ClingSTUN digs in. It copies itself to hidden folders and registers startup entries so it relaunches automatically after a reboot. It kills competing malware that might draw attention, then disguises its own process information to resemble the device's core startup software. A quick inspection turns up nothing suspicious.

What gear is at risk?

Fortinet confirmed targets across product families including D-Link hardware, TP-Link Archer AX21 routers, and AVTECH cameras. The malware exploits known, unpatched flaws: command injection (where attackers send instructions the device's software mistakenly runs as legitimate commands), and buffer overflows (where attackers send more data than a program expects, overwriting memory to hijack it). Fortinet says the malware contains exploits for seven vulnerabilities and continues to incorporate new ones as the campaign evolves.

Architecture supported Example hardware type
ARM Most home routers, cameras
Intel 80386 Older embedded controllers
MIPS Many consumer routers
PowerPC Older networking gear
x86-64 NAS devices, some DVRs

Five chip families, one build, a very large pool of targets.

The failure mode is familiar. Manufacturers stop issuing updates for older products. IT teams don't always track which network devices are running what firmware. A device sits on the internet for years, unpatched, until someone scans for the known flaw and drops a payload. Louis Eichenbaum, federal CTO at ColorTokens, told CSO Online that attackers keep targeting known vulnerabilities "because those weaknesses remain effective."

The post-mortem will say the patch was available. It usually is.

Should you worry?

Own any of the named hardware? Check for a firmware update and apply it. Manufacturers that no longer support a device leave you one real option: replace it. Short of that, blocking the device from reaching the open internet directly, by placing it behind a firewall that limits what it can talk to, cuts most of what ClingSTUN needs to operate.

For network administrators: watch for unexpected UDP traffic and repeated STUN requests from devices that have no reason to make video calls.

© 2026 Threat Vectr