Cookie Consent by Free Privacy Policy Generator

ClingSTUN malware: IoT devices exploited to create proxy networks

A new Linux backdoor called ClingSTUN is targeting unpatched IoT devices by exploiting 24 known vulnerabilities to gain initial access, then establishing persistence and using legitimate public STUN servers to obscure command and control communications, according to Infosecurity Magazine reporting on 5 October 2026. The malware operates as a back-connect proxy, turning compromised devices into nodes that can be used to relay traffic, mask attacker activity or provide persistent access to internal networks. ClingSTUN is designed to self-propagate by scanning for vulnerable devices and exploiting known flaws in routers, cameras, network-attached storage and other IoT equipment. Security researchers note that the use of public STUN servers, which are commonly used for legitimate network traversal in VoIP and video conferencing, makes the malware's communications harder to detect and block.

Why this matters for UK organisations

This threat is particularly relevant for UK organisations because many businesses deploy IoT devices at the network edge, in branch offices, in operational technology environments or in facilities management systems, often without the same level of patch management, monitoring or segmentation applied to traditional IT infrastructure. Compromised IoT devices can provide attackers with a foothold inside the network, a platform for lateral movement, or a proxy node that allows them to obscure their activity and evade detection. The fact that ClingSTUN exploits known vulnerabilities rather than zero-days means that the risk is entirely preventable through timely patching and proper device hygiene, but many organisations struggle to maintain visibility and control over IoT assets, particularly where those devices are managed by third parties or deployed outside the core IT estate. This is especially relevant for organisations in manufacturing, retail, healthcare, education and facilities management, where IoT devices are often deployed widely and managed inconsistently.

What to review

UK businesses should review how IoT devices are inventoried, patched and monitored across the organisation. Consider whether you have visibility into all internet-facing IoT equipment, whether firmware updates are applied consistently, and whether these devices are segmented from critical systems. This is also an opportunity to assess whether third-party managed devices, such as building management systems, security cameras or industrial control equipment, are included in your patch management and monitoring processes, or whether they represent an unmanaged risk. Organisations should also consider whether IoT devices are subject to the same access controls, logging and monitoring as traditional IT assets, and whether network segmentation is in place to limit the impact if a device is compromised. Where IoT devices are managed by third parties, ensure that patching responsibilities, monitoring arrangements and incident response procedures are clearly defined and regularly reviewed.

Source: Infosecurity Magazine

News and blog posts
Today's brief highlights the operational challenges organisations face when...
Unauthorised parties accessed names, addresses and personal identification...
Citrix has disclosed a third actively exploited zero-day vulnerability in its...
Google has temporarily stopped accepting product vulnerability reports through...