Cling Malware Disguised as Google STUN Traffic Controls IoT Devices
Key Takeaways Cling malware is forming a botnet by compromising IoT devices, primarily through vulnerabilities in Realtek software. The malware cleverly disguises its command-and-control (C2) traffic...
Key Takeaways
- Cling malware is forming a botnet by compromising IoT devices, primarily through vulnerabilities in Realtek software.
- The malware cleverly disguises its command-and-control (C2) traffic as legitimate STUN (Session Traversal Utilities for NAT) communications from Google’s public STUN service.
- Infected devices are capable of participating in denial-of-service attacks, relaying traffic, and opening tunnels, posing significant risks to targeted infrastructure.
- While no confirmed outages have been reported, researchers observed attack instructions targeting an internet provider, university infrastructure, and gaming services.
- Mitigation involves patching vulnerable Realtek SDKs, restricting inbound access, and monitoring for anomalous STUN traffic and specific malware artifacts.
Cling Malware Leverages Google STUN Traffic as Cover for IoT Botnet Operations
A new malware strain, dubbed Cling, is actively compromising internet-connected devices to create a botnet, employing a sophisticated technique that camouflages its command-and-control communications as standard replies from Google’s public STUN service. This deceptive approach allows attacker instructions to blend seamlessly with routine network traffic, making detection challenging for conventional security measures.
Table Of Content
The infection chain typically initiates with attacks targeting exposed devices that run vulnerable Realtek software. This entry point, involving older flaws in the Realtek SDK, has been previously documented in other exploitation campaigns, highlighting the persistent risk posed by unpatched routers, access points, repeaters, and similar network appliances.
Researchers at Nozomi Networks identified Cling during their investigation into a surge of exploitation attempts against CVE-2021-35394. In a report, Nozomi Networks said in a report that the malware exploits seemingly legitimate STUN exchanges to register compromised devices and relay operator commands.
The analysis, published on October 1, 2026, details a robust botnet infrastructure capable of self-propagation, traffic relaying, tunnel creation, and the execution of denial-of-service (DoS) attacks. While Nozomi Networks observed attack instructions directed at an internet service provider, university infrastructure, and gaming platforms, the total number of infected devices and any confirmed service disruptions remain undisclosed.
Cling Malware Masquerades as Google STUN Traffic
STUN, or Session Traversal Utilities for NAT, is a critical protocol that helps devices determine their public IP address and the network port assigned by their router. It is widely used in applications like video conferencing and browser-based communications, generating a constant stream of background traffic that attackers can mimic to evade detection.
Cling malware operates by contacting 13 hardcoded STUN servers approximately every five seconds. It then collects the port information returned by these services and sends a separate registration message. This message contains the mapped ports along with a unique tag indicating the device’s infection vector. Nozomi Networks detailed this process, noting that these registration messages are not valid STUN traffic and were typically ignored by legitimate servers during testing.
However, one particular server returned an anomalous response that failed to correctly echo a request identifier, prompting researchers to investigate its connection to the botnet. The research team conducted controlled experiments, advertising different port sets to each server while simulating the registration of an infected device. Several hours later, commands were received on ports that had only been disclosed to the suspicious server, confirming its role in the botnet’s command-and-control operations. The researchers further explained that commands are embedded within the protocol’s 12-byte transaction identifier, a field typically used to match requests with their corresponding replies.
This method of camouflage is reminiscent of browser-based malware command channels that similarly exploit common communication patterns, though Cling utilizes UDP rather than a hijacked browser. The command packets observed by the researchers appeared to originate from Google’s STUN infrastructure. Nozomi Networks assessed source-address spoofing as the most probable explanation for this, supported by discrepancies in packet lifetime values.
Crucially, the researchers found no evidence suggesting that Google’s servers were compromised or actively transmitting these instructions. This distinction is vital for investigations, as most listed STUN endpoints are legitimate public services, not confirmed attacker infrastructure. Their presence in network traffic should therefore be evaluated in conjunction with protocol anomalies and unusual device behavior, rather than solely relying on the reputation of the apparent source.
Persistence and Defense
Initial exploitation grants attackers the ability to execute shell commands, enabling the download and execution of the Cling malware. The analyzed sample also incorporates exploits for several other vulnerabilities, including CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, and CVE-2016-20016. This broad array of exploits expands its potential reach across various routers and video-recording equipment.
Once infected, Cling establishes persistence by creating hidden copies of itself and adding startup entries to ensure survival across reboots. It also replaces standard download utilities while retaining access to the original program. This allows routine maintenance tasks or subsequent downloads to inadvertently trigger the malware again. Operators of the Cling botnet can download additional payloads, initiate or halt scanning activities, establish TCP tunnels, enable proxy relays, and orchestrate flooding attacks. Such capabilities underscore how compromised edge devices can be repurposed as infrastructure for a wide range of malicious activities, extending beyond the initial intrusion, as seen with operations like PolarEdge IoT proxy networks.
The analysis primarily focused on a MIPS sample, with supporting observations from related files. It is important to note that the described persistence and command features are specific to the examined sample and may not apply universally to all Cling variants.
What You Should Do
- Patch Vulnerabilities: Immediately apply available security patches for all exposed Realtek SDK vulnerabilities, particularly CVE-2021-35394, on routers, access points, and other IoT devices.
- Restrict Inbound Access: Where patching is not feasible, implement strict network segmentation and firewall rules to restrict inbound access to vulnerable devices.
- Monitor STUN Traffic: Implement network monitoring to detect frequent STUN requests with all-zero transaction identifiers, unexpected UDP registration messages, and any STUN connections that deviate from a device’s normal behavior.
- Inspect Device Configuration: Regularly review device startup configurations (e.g.,
/etc/inittab,/etc/init.d/rcS,/etc/rc.d/rc.boot) and check for replaced download utilities (e.g.,wget.r,wget.p) for artifacts detailed in the Nozomi Networks report. - Utilize IoCs for Detection: Incorporate the provided Indicators of Compromise (IoCs), including SHA-1/SHA-256 hashes, loader URLs, STUN endpoints, and specific file paths, into your threat intelligence platforms (e.g., SIEM, EDR) and network security tools for proactive detection.
- Educate on Spoofing: Understand that the apparent source IP of command traffic can be spoofed. Do not solely rely on the reputation of a STUN server to establish the safety of communications.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.