Back to Intelligence

ClingSTUN Linux Back-Connect Proxy Abusing Public STUN: OTX Pulse Detection Pack for IoT and Edge Exploitation

SA
Security Arsenal Team
October 6, 2026
9 min read

TLP: WHITE

Threat Summary

The OTX pulse describes ClingSTUN, a Linux backdoor reported by AlienVault and linked to a Fortinet research write-up, that compromises Internet-facing and IoT-class devices by exploiting a broad set of known CVEs. The activity is consistent with an opportunistic, exposure-driven campaign rather than a narrow vertical operation: no targeted industries or countries are listed, the adversary is unknown, and the indicator set is dominated by vulnerability identifiers rather than bespoke intrusion infrastructure.

The attack chain is best read as: scan for reachable embedded services, exploit one of many command-injection or remote-code-execution flaws across vendor products, drop or fetch a Linux payload, execute from writable transient paths, establish persistence, and then operate as a back-connect proxy. The notable tradecraft is abuse of legitimate public STUN infrastructure. STUN is normally used by VoIP, WebRTC, and NAT traversal stacks to discover external IP and port mappings. ClingSTUN reportedly uses that benign protocol and ecosystem to learn its externally mapped address and support proxy/back-connect behavior, blending into traffic that defenders often allow outbound.

The objective is most likely resilient access and traffic relay, not immediate data theft. A device that can discover its NAT mapping and accept back-connects is useful for proxying criminal traffic, hiding operator origin, staging follow-on payloads, and converting consumer or edge hardware into botnet capacity.

Threat Actor / Malware Profile

Attribution: Unknown. Treat this as criminal tooling with botnet/proxy economics until infrastructure clustering proves otherwise.

Malware: ClingSTUN Linux backdoor.

Likely distribution method: Mass exploitation of unpatched Internet-exposed services using CVEs referenced in the pulse, including CVE-2014-8361, CVE-2019-7256, CVE-2019-17621, CVE-2021-35394, CVE-2016-20016, CVE-2021-36380, CVE-2022-36553, CVE-2022-37055, and tag-referenced CVEs such as CVE-2024-21887, CVE-2024-7029, CVE-2023-41011, CVE-2022-35555, CVE-2024-32314, CVE-2026-87827, CVE-2024-46048, and CVE-2021-35394. Several of these classes align with embedded web interfaces, SDK command injection, VPN edge appliances, camera/NVR stacks, and router services.

Payload behavior: After code execution, expect shell or BusyBox-style post-exploitation: download from a staging URL, write to /tmp, /var/tmp, /dev/shm, or a user-writable directory, chmod +x, execute, remove obvious artifacts, and maintain a low-profile resident process. The proxy function means inbound tasks may arrive through outbound sessions rather than a classic listening C2 port.

C2 communication: Public STUN services over UDP 3478 and TCP/UDP 5349 are the key behavioral pivot. The malware likely sends STUN binding-style requests to learn reflexive transport addresses, then uses that mapping to coordinate back-connect proxy connectivity. Defenders should treat unexpected STUN from servers, cameras, routers, DVRs, Linux appliances, or container hosts as suspicious, especially when the initiating process is not a known collaboration/media stack.

Persistence mechanism: On full Linux systems, expect systemd service or timer creation, cron entries, rc.local or init scripts, shell profile injection, or watchdog-style respawn loops. On IoT firmware, persistence may be as simple as surviving until reboot while the bot re-exploits the device, or modifying writable configuration partitions where available.

Anti-analysis techniques: Use of legitimate STUN infrastructure reduces indicator fidelity and complicates blocking. Generic Linux payloads often use stripped binaries, randomized filenames in temporary paths, short-lived downloaders, environment or process-name masquerading as kworker, sshd, cron, update, or system services, and deletion of downloader artifacts after execution.

IOC Analysis

This pulse sample is dominated by CVE indicators, not hashes, IPs, or domains. That matters operationally: do not try to solve this with a blocklist alone. CVEs are exposure indicators. They tell the SOC and vulnerability team which attack paths are being actively absorbed into botnet tooling.

Operationalize the indicators in four lanes:

  1. Exposure management: Match CVE-2014-8361, CVE-2019-7256, CVE-2019-17621, CVE-2021-35394, CVE-2016-20016, CVE-2021-36380, CVE-2022-36553, CVE-2022-37055 and the tag CVEs against internet-facing assets, edge VPNs, cameras, NVRs, routers, NAS, embedded Linux, and vendor appliances. Prioritize devices with management interfaces reachable from the Internet or flat reachable from user VLANs.

  2. Behavioral detection: Since infrastructure may be legitimate public STUN, detect the process-to-protocol mismatch. A workstation running Teams or Zoom using STUN is normal; a DVR, switch controller, Linux server, or container spawning curl, wget, sh, python, perl, busybox, or an unknown binary and then emitting STUN is not.

  3. File and execution telemetry: Hunt writable-path execution, ELF binaries dropped in temporary directories, chmod +x followed by execution, and persistence writes to systemd, cron, init, profile.d, or firmware configuration locations.

  4. Tooling: Use EDR for process and network lineage, firewall or Zeek/Suricata for UDP 3478 and TCP/UDP 5349 egress baselining, vulnerability scanners for CVE coverage, and asset inventory to identify embedded devices that cannot run agents. For STUN-aware network analytics, Zeek can flag UDP 3478 while Suricata can alert on unusual STUN binding request volume; EDR supplies the missing process context.

Detection Engineering

YAML
---
title: Linux Unexpected STUN NAT Traversal Egress
id: 7f2a1b10-6c2b-4f3f-9d8c-clingstun0001
status: experimental
description: Detects non-media Linux processes initiating STUN/TURN egress consistent with ClingSTUN discovering external NAT mappings or preparing back-connect proxy traffic.
references:
  - https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure
  - https://otx.alienvault.com/
date: 2026/10/06
modified: 2026/10/06
author: Security Arsenal
logsource:
  product: linux
  category: network_connection
detection:
  selection_ports:
    DestinationPort:
      - 3478
      - 5349
  selection_protocol:
    Protocol:
      - udp
      - tcp
  filter_known_media:
    Image|endswith:
      - /zoom
      - /teams
      - /firefox
      - /chrome
      - /webrtc
  condition: selection_ports and selection_protocol and not filter_known_media
falsepositives:
  - WebRTC gateways, SBCs, VoIP services, meeting room appliances
level: high
tags:
  - attack.t1090
  - attack.t1071
  - attack.t1572
---
title: Linux Suspicious Writable Path Execution After Download
id: 7f2a1b10-6c2b-4f3f-9d8c-clingstun0002
status: experimental
description: Detects shell or download tools staging and executing ELF payloads from temporary or memory-backed paths, a common IoT botnet post-exploitation pattern.
references:
  - https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure
  - https://otx.alienvault.com/
date: 2026/10/06
modified: 2026/10/06
author: Security Arsenal
logsource:
  product: linux
  category: process_creation
detection:
  selection_downloader:
    Image|endswith:
      - /curl
      - /wget
      - /busybox
      - /sh
      - /bash
      - /python
      - /perl
  selection_tmp_paths:
    CommandLine|contains:
      - /tmp/
      - /var/tmp/
      - /dev/shm/
      - /run/user/
  selection_exec_markers:
    CommandLine|contains:
      - chmod +x
      - chmod 777
      - ./
      - nohup
      - setsid
  condition: selection_downloader and selection_tmp_paths and selection_exec_markers
falsepositives:
  - Package managers, configuration management, legitimate admin scripts
level: high
tags:
  - attack.t1105
  - attack.t1059
  - attack.t1222
---
title: Linux Persistence Creation for Proxy Backdoor Survival
id: 7f2a1b10-6c2b-4f3f-9d8c-clingstun0003
status: experimental
description: Detects service, timer, cron, init, or profile persistence creation shortly after suspicious shell activity, consistent with backdoor survival on compromised Linux hosts.
references:
  - https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure
  - https://otx.alienvault.com/
date: 2026/10/06
modified: 2026/10/06
author: Security Arsenal
logsource:
  product: linux
  category: process_creation
detection:
  selection_persist_cmd:
    CommandLine|contains:
      - systemctl enable
      - systemctl start
      - crontab
      - /etc/cron
      - /etc/systemd/system/
      - /etc/init.d/
      - rc.local
      - profile.d
      - update-rc.d
  selection_context:
    Image|endswith:
      - /sh
      - /bash
      - /systemctl
      - /crontab
      - /sed
      - /tee
      - /cp
  filter_admin:
    User|contains:
      - ansible
      - root_approved_change
  condition: selection_persist_cmd and selection_context and not filter_admin
falsepositives:
  - Administrator maintenance, MDM, configuration management
level: medium
tags:
  - attack.t1543
  - attack.t1053
  - attack.t1037
KQL — Microsoft Sentinel / Defender
let stun_ports = dynamic([3478,5349]);
let risky_proc = dynamic(['curl','wget','busybox','sh','bash','python','python3','perl','php','nc','ncat','socat','stun','turn','clingstun']);
let net = DeviceNetworkEvents
| where TimeGenerated >= ago(7d)
| where RemotePort in (stun_ports)
| where InitiatingProcessFileName has_any (risky_proc)
     or InitiatingProcessCommandLine has_any ('stun','turn','3478','5349','/tmp/','/var/tmp/','/dev/shm/')
| project net_Time=TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemotePort, RemoteUrl, ReportId;
let proc = DeviceProcessEvents
| where TimeGenerated >= ago(7d)
| where ProcessCommandLine has_any ('/tmp/','/var/tmp/','/dev/shm/','chmod +x','systemctl enable','crontab','/etc/systemd/system','rc.local','profile.d')
     or FileName has_any (risky_proc)
| project proc_Time=TimeGenerated, DeviceName, FileName, ProcessCommandLine, FolderPath, SHA256, ReportId;
net
| join kind=leftouter proc on DeviceName
| where proc_Time between (net_Time - 30m .. net_Time + 30m) or isnull(proc_Time)
| summarize FirstSeen=min(net_Time), LastSeen=max(net_Time), STUNPeers=make_set(RemoteIP), Ports=make_set(RemotePort), Commands=make_set(InitiatingProcessCommandLine), NearbyProcess=make_set(ProcessCommandLine) by DeviceName, InitiatingProcessFileName
| order by FirstSeen desc;
Bash / Shell
#!/usr/bin/env bash
set -u
printf '[*] ClingSTUN quick hunt: %s\n' "$(date -u +%FT%TZ)"
printf '\n[processes with temp or masquerade markers]\n'
ps -eo pid,user,comm,args | grep -Ei '(/tmp/|/var/tmp/|/dev/shm/|clingstun|stun|turn|kworker|update|curl|wget|busybox)' | grep -v grep || true
printf '\n[executable files in writable transient paths]\n'
for d in /tmp /var/tmp /dev/shm /run/user; do [ -d "$d" ] && find "$d" -xdev -type f -perm -111 -mtime -14 -ls 2>/dev/null; done || true
printf '\n[recent ELF drops]\n'
for d in /tmp /var/tmp /dev/shm; do [ -d "$d" ] && find "$d" -xdev -type f -mtime -14 -exec sh -c 'head -c 4 "$1" 2>/dev/null | grep -q "^.ELF" && ls -l "$1"' sh {} \; 2>/dev/null; done || true
printf '\n[persistence artifacts]\n'
ls -l /etc/cron* /var/spool/cron 2>/dev/null || true
grep -RniE 'tmp|dev/shm|wget|curl|stun|3478|5349' /etc/cron* /var/spool/cron /etc/rc.local /etc/profile.d 2>/dev/null || true
systemctl list-unit-files --no-pager 2>/dev/null | grep -Ei 'stun|proxy|update|tmp|camera|watchdog' || true
find /etc/systemd/system /lib/systemd/system -type f -mtime -14 -print 2>/dev/null | xargs -r grep -niE 'ExecStart=.*(/tmp|/var/tmp|/dev/shm)|curl|wget|stun|3478|5349' 2>/dev/null || true
printf '\n[network: STUN/TURN and suspicious egress]\n'
if command -v ss >/dev/null 2>&1; then ss -antup 2>/dev/null | grep -E ':(3478|5349)\b' || true; fi
if command -v netstat >/dev/null 2>&1; then netstat -antup 2>/dev/null | grep -E ':(3478|5349)\b' || true; fi
printf '\n[listen and raw socket inventory]\n'
ss -lntup 2>/dev/null || netstat -lntup 2>/dev/null || true
printf '\n[done] export full ps, ss, journalctl -u relevant units, and firewall logs for triage.\n'

Response Priorities

Immediate

  • Treat CVEs as active exploitation intelligence: verify external exposure and emergency-patch or isolate affected edge VPNs, routers, cameras, NVRs, NAS, controllers, and Linux servers.
  • Do not broadly block public STUN if collaboration traffic depends on it. Instead, alert on process-context mismatch and block known bad egress only after validation.
  • Hunt for UDP/TCP 3478 and 5349 initiated by non-media binaries, plus execution from /tmp, /var/tmp, and /dev/shm.
  • Capture volatile evidence before reboot: process list, socket table, systemd units, cron, recent temporary files, and egress connections.

24 hours

  • This pulse is not credential-stealer focused, but compromised edge appliances often expose admin secrets, VPN accounts, Wi-Fi keys, or management tokens. Rotate credentials stored on any device showing exploitation or persistence artifacts.
  • Confirm whether any affected device had unmanaged local admin, reused passwords, default credentials, or cloud-management tokens.
  • Baseline which assets legitimately require STUN/TURN and create an allowlist by process path, host role, and destination service.

1 week

  • Remove inbound management exposure; place device administration behind VPN/ZTNA and restrict management to jump hosts.
  • Segment IoT and OT away from servers and user networks; deny IoT-initiated outbound except required update, NTP, DNS, and approved media services.
  • Deploy network detection for STUN anomalies and EDR coverage where supported; for agentless embedded devices, use DHCP/DNS/NetFlow/Zeek metadata and strict egress policy.
  • Add exploit-specific signatures and virtual patching for the listed CVEs, then validate with authenticated scans and attack-path review.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.