Tidavo
Tuesday 6 October 2026

Linux Botnet Exploits Known Flaws to Convert Network Hardware Into Hidden Relay Nodes

Malware tracked as ClingSTUN abuses common networking protocols to mask compromised office and industrial equipment behind legitimate internet traffic.

6 Oct 2026

A newly discovered malware campaign is targeting connected hardware across enterprise and industrial networks, turning compromised gear into silent digital conduits. The program, identified in security findings under names including Cling and ClingSTUN, focuses on Linux-powered Internet of Things systems that have been left exposed to the wider internet.

Researchers from Fortinet and Nozomi Networks discovered that the intrusions rely on known, documented software bugs rather than novel vulnerabilities. The campaign strikes hardware from multiple brands, including routers, security camera recorders, and communication gateways made by vendors such as D-Link, TP-Link, Ivanti, and Realtek.

The central feature distinguishing this malware is its use of the Session Traversal Utilities for NAT protocol, commonly known as STUN. In ordinary network operations, STUN servers assist devices sitting behind corporate firewalls or home routers by identifying their outward-facing internet addresses, ensuring that video conferences and voice calls can connect directly.

Rather than creating a bespoke communication system that might attract scrutiny, the malware sends queries to legitimate public STUN servers. By doing so, the software discovers how each infected machine appears to the outside internet and identifies which communication ports are reachable from external systems.

Because millions of ordinary consumer and office applications query STUN servers every day, this signaling easily blends into normal network activity. Network defenders cannot simply block all STUN traffic without disabling legitimate communication tools such as voice-over-IP handsets and web conferencing software.

Researchers offer different assessments of how attackers direct these compromised machines: Fortinet reported that it found no separate control server and that the exact method for delivering commands through firewalls remains unconfirmed, while Nozomi Networks concluded that the STUN traffic itself acts as a working command channel.

The campaign reaches vulnerable hardware through an extensive catalog of at least twenty-four previously disclosed security weaknesses. These range from an aviation data distribution bug cataloged in 2021 to vulnerabilities identified as recently as 2026 in cellular networking components, alongside flaws impacting the Realtek Jungle software development kit.

Once the malware secures a foothold on a machine, it establishes automated persistence to ensure it survives reboots. It then deploys an additional built-in arsenal of seven separate exploits designed to probe surrounding hardware and infect other systems across connected subnets.

The secondary exploits allow the malware to self-propagate across an array of brands, including equipment from Linksys, MVPower, TBK, LB-LINK, China Mobile, and KGUARD. The tools cover vulnerabilities dating from a decade-old remote execution bug up to video recorder flaws documented in 2026.

By taking control of these network edge devices, the operators can transform them into proxy nodes. Any traffic the attackers choose to route through the hijacked machine emerges onto the internet carrying the public address of the victim organization rather than the attacker's own location.

This arrangement exposes affected organizations to significant fallout. Their public internet addresses risk being added to security blacklists, operational bandwidth is consumed by unauthorized transfers, and poorly isolated devices can give intruders an open path into internal corporate systems.

Defending against the threat requires inspecting network behavior rather than relying solely on blacklists. Security specialists advise monitoring for abnormal activity, such as a single piece of office hardware opening numerous unusual transmission sockets or repeatedly pinging dozens of distinct STUN destinations.

Analysts also stress the necessity of maintaining comprehensive equipment inventories and applying firmware patches as soon as vendors release them. Devices that cannot receive prompt updates should have their vulnerable services disabled or be placed behind protected administrative gateways that require multifactor authentication.

Dark Reading , The Hacker News