Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor
FortiGuard Labs has identified a Linux backdoor that exploits known vulnerabilities in internet-facing devices and converts infected systems into remotely controlled proxy nodes.
Named ClingSTUN, the malware supports remote command execution, maintains access after a reboot and uses legitimate public STUN servers to communicate through network address translation.
Known Vulnerabilities Used for Initial Access
According to the company’s report shared with Hackread.com ahead of publication on Monday, October 5, 2026, attackers behind the campaign exploited about two dozen vulnerabilities affecting products from:
- Avtech
- D-Link
- EnGenius
- Hytec
- Ivanti
- Lantronix
- Linear
- MeiG
- Realtek
- Sunhillo
- Tenda
- TP-Link
FortiGuard also found seven hardcoded exploits that ClingSTUN can use to spread to other vulnerable devices. Those flaws affect products from:
- China Mobile
- KGUARD
- Linksys
- LB-LINK
- MVPower
- Realtek
- TBK
Downloaders recovered during the investigation could install ClingSTUN on several processor architectures, including AMD x86-64, ARM, Intel 80386, MIPS R3000 and PowerPC. This allows the campaign to...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE