ClingSTUN Malware Exploits IoT Vulnerabilities Using Public STUN Servers
Researchers have identified a new Linux-based malware called ClingSTUN that exploits at least 24 known security flaws across various IoT devices, including routers and surveillance systems from multiple manufacturers. The malware leverages legitimate public STUN servers to maintain covert communication with infected devices, avoiding detection by traditional command-and-control infrastructure. The attacks target vulnerabilities dating from 2021 to earlier this year, indicating a broad and ongoing exploitation effort.
GoKawiil's interpretation of the reporting above, not reported fact.
This development highlights how attackers are increasingly using legitimate internet protocols like STUN to hide malicious activity, complicating detection and mitigation efforts. The widespread vulnerabilities across popular IoT devices suggest that many networks could be at risk of persistent compromise, especially as attackers expand their exploitation techniques. Understanding this method could help security teams better identify and defend against such covert operations.
- ClingSTUN exploits multiple IoT vulnerabilities to maintain access.
- Legitimate STUN servers are used to hide malicious activity.
- The attack targets a broad range of IoT devices from various manufacturers.
Source: darkreading.com — Jai Vijayan, 2026-10-05
Published there as: “ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.