ClingSTUN botnet exploits old flaws in routers and VPN gateways
The malware targets more than 30 known vulnerabilities, including two Ivanti flaws that prompted an Australian Cyber Security Centre alert in January 2024.
By Quang Dinh

A Linux botnet is exploiting more than 30 known security flaws to take over internet-connected equipment, FortiGuard Labs researchers have found. Named ClingSTUN, the malware lets remote operators use infected routers, cameras, video recorders and VPN gateways as proxies to route traffic.
Its targets include Ivanti Connect Secure and Policy Secure vulnerabilities CVE-2023-46805 and CVE-2024-21887. Attackers began combining the flaws as zero-days as early as December 2023. In January 2024, the Australian Cyber Security Centre warned about the vulnerabilities affecting Ivanti's remote access solution.
Much of the equipment identified by FortiGuard is intended for consumers and small businesses, including devices from D-Link, TP-Link and Tenda. Most of the flaws allow attackers to inject commands through a device's web interface.
After gaining access, ClingSTUN installs a compatible build, disables a safety timer that could reboot the device and alters start-up scripts to survive restarts. The latest version also removes competing malware. Infected devices can attack others using seven additional flaws, including a Realtek vulnerability dating from 2014.
The botnet uses public STUN servers, normally used by browsers and calling apps, to discover its external address and port and maintain a router mapping. Fortinet said this traffic can resemble legitimate calling activity and cautioned against classifying those servers as attacker infrastructure.
FortiGuard Labs researcher Vincent Li said no separate coordination server had been identified for the mapping step. How operators obtain those mappings and send control traffic into internal networks remains unverified.



