Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Top 10 Certificate Lifecycle Management Tools for 2026
October 5, 2026
Cling Malware Disguised as Google STUN Traffic Controls IoT Devices
October 5, 2026
Top Fine-Grained Authorization Tools for 2026
October 5, 2026
Home/CyberSecurity News/Cling Malware Disguised as Google STUN Traffic Controls IoT Devices
CyberSecurity News

Cling Malware Disguised as Google STUN Traffic Controls IoT Devices

Key Takeaways Cling malware is forming a botnet by compromising IoT devices, primarily through vulnerabilities in Realtek software. The malware cleverly disguises its command-and-control (C2) traffic...

Sarah simpson
Sarah simpson
October 5, 2026 7 Min Read
2 0

Key Takeaways

  • Cling malware is forming a botnet by compromising IoT devices, primarily through vulnerabilities in Realtek software.
  • The malware cleverly disguises its command-and-control (C2) traffic as legitimate STUN (Session Traversal Utilities for NAT) communications from Google’s public STUN service.
  • Infected devices are capable of participating in denial-of-service attacks, relaying traffic, and opening tunnels, posing significant risks to targeted infrastructure.
  • While no confirmed outages have been reported, researchers observed attack instructions targeting an internet provider, university infrastructure, and gaming services.
  • Mitigation involves patching vulnerable Realtek SDKs, restricting inbound access, and monitoring for anomalous STUN traffic and specific malware artifacts.

Cling Malware Leverages Google STUN Traffic as Cover for IoT Botnet Operations

A new malware strain, dubbed Cling, is actively compromising internet-connected devices to create a botnet, employing a sophisticated technique that camouflages its command-and-control communications as standard replies from Google’s public STUN service. This deceptive approach allows attacker instructions to blend seamlessly with routine network traffic, making detection challenging for conventional security measures.

Table Of Content

  • Key Takeaways
  • Cling Malware Leverages Google STUN Traffic as Cover for IoT Botnet Operations
  • Cling Malware Masquerades as Google STUN Traffic
  • Persistence and Defense
  • What You Should Do

The infection chain typically initiates with attacks targeting exposed devices that run vulnerable Realtek software. This entry point, involving older flaws in the Realtek SDK, has been previously documented in other exploitation campaigns, highlighting the persistent risk posed by unpatched routers, access points, repeaters, and similar network appliances.

Researchers at Nozomi Networks identified Cling during their investigation into a surge of exploitation attempts against CVE-2021-35394. In a report, Nozomi Networks said in a report that the malware exploits seemingly legitimate STUN exchanges to register compromised devices and relay operator commands.

The analysis, published on October 1, 2026, details a robust botnet infrastructure capable of self-propagation, traffic relaying, tunnel creation, and the execution of denial-of-service (DoS) attacks. While Nozomi Networks observed attack instructions directed at an internet service provider, university infrastructure, and gaming platforms, the total number of infected devices and any confirmed service disruptions remain undisclosed.

Cling Malware Masquerades as Google STUN Traffic

STUN, or Session Traversal Utilities for NAT, is a critical protocol that helps devices determine their public IP address and the network port assigned by their router. It is widely used in applications like video conferencing and browser-based communications, generating a constant stream of background traffic that attackers can mimic to evade detection.

Cling malware operates by contacting 13 hardcoded STUN servers approximately every five seconds. It then collects the port information returned by these services and sends a separate registration message. This message contains the mapped ports along with a unique tag indicating the device’s infection vector. Nozomi Networks detailed this process, noting that these registration messages are not valid STUN traffic and were typically ignored by legitimate servers during testing.

However, one particular server returned an anomalous response that failed to correctly echo a request identifier, prompting researchers to investigate its connection to the botnet. The research team conducted controlled experiments, advertising different port sets to each server while simulating the registration of an infected device. Several hours later, commands were received on ports that had only been disclosed to the suspicious server, confirming its role in the botnet’s command-and-control operations. The researchers further explained that commands are embedded within the protocol’s 12-byte transaction identifier, a field typically used to match requests with their corresponding replies.

This method of camouflage is reminiscent of browser-based malware command channels that similarly exploit common communication patterns, though Cling utilizes UDP rather than a hijacked browser. The command packets observed by the researchers appeared to originate from Google’s STUN infrastructure. Nozomi Networks assessed source-address spoofing as the most probable explanation for this, supported by discrepancies in packet lifetime values.

Crucially, the researchers found no evidence suggesting that Google’s servers were compromised or actively transmitting these instructions. This distinction is vital for investigations, as most listed STUN endpoints are legitimate public services, not confirmed attacker infrastructure. Their presence in network traffic should therefore be evaluated in conjunction with protocol anomalies and unusual device behavior, rather than solely relying on the reputation of the apparent source.

Persistence and Defense

Initial exploitation grants attackers the ability to execute shell commands, enabling the download and execution of the Cling malware. The analyzed sample also incorporates exploits for several other vulnerabilities, including CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, and CVE-2016-20016. This broad array of exploits expands its potential reach across various routers and video-recording equipment.

Once infected, Cling establishes persistence by creating hidden copies of itself and adding startup entries to ensure survival across reboots. It also replaces standard download utilities while retaining access to the original program. This allows routine maintenance tasks or subsequent downloads to inadvertently trigger the malware again. Operators of the Cling botnet can download additional payloads, initiate or halt scanning activities, establish TCP tunnels, enable proxy relays, and orchestrate flooding attacks. Such capabilities underscore how compromised edge devices can be repurposed as infrastructure for a wide range of malicious activities, extending beyond the initial intrusion, as seen with operations like PolarEdge IoT proxy networks.

The analysis primarily focused on a MIPS sample, with supporting observations from related files. It is important to note that the described persistence and command features are specific to the examined sample and may not apply universally to all Cling variants.

What You Should Do

  • Patch Vulnerabilities: Immediately apply available security patches for all exposed Realtek SDK vulnerabilities, particularly CVE-2021-35394, on routers, access points, and other IoT devices.
  • Restrict Inbound Access: Where patching is not feasible, implement strict network segmentation and firewall rules to restrict inbound access to vulnerable devices.
  • Monitor STUN Traffic: Implement network monitoring to detect frequent STUN requests with all-zero transaction identifiers, unexpected UDP registration messages, and any STUN connections that deviate from a device’s normal behavior.
  • Inspect Device Configuration: Regularly review device startup configurations (e.g., /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot) and check for replaced download utilities (e.g., wget.r, wget.p) for artifacts detailed in the Nozomi Networks report.
  • Utilize IoCs for Detection: Incorporate the provided Indicators of Compromise (IoCs), including SHA-1/SHA-256 hashes, loader URLs, STUN endpoints, and specific file paths, into your threat intelligence platforms (e.g., SIEM, EDR) and network security tools for proactive detection.
  • Educate on Spoofing: Understand that the apparent source IP of command traffic can be spoofed. Do not solely rely on the reputation of a STUN server to establish the safety of communications.
Type Indicator Description
SHA-1 3b0ac6aaabb3bf8058ca14f9c8ccc613cfa3ea71 Primary MIPS sample analyzed by researchers.
SHA-1 08636d09d9ffd1713bd6bcb965ad40b6ce3de1aa Additional MIPS sample listed in the report.
SHA-256 90d738a8d650e3fefda9d7efa4baa11bd89ab05fcf0eb173e04aa01a52b465e2 Sample hash included in the source YARA rule metadata.
SHA-256 3a6927a3399f2a10bb2e2229482e5096e5f1c3401a87f7f1730db11243531e28 Second sample hash included in the source YARA rule metadata.
Loader URL hxxp://118.45.196[.]225:800/mipsel Malware loader location listed in the source.
Loader URL hxxp://120.193.219[.]210:800/mipsel Malware loader location listed in the source.
Loader URL hxxp://58.211.144[.]243:800/mipsel Malware loader location listed in the source.
Loader endpoint 121[.]32.243.81:1337 Loader specified in an observed scan-and-exploit command.
IP address 145.249.115[.]184 STUN server linked to operator access through controlled registration testing.
STUN endpoint 74.125.250.129:19302 Public Google STUN endpoint contacted by Cling; not established as compromised.
STUN endpoint 145.249.115.184:3478 Hardcoded endpoint associated with the suspicious STUN server.
STUN endpoint 216.93.246.18:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 85.17.88.164:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 77.72.169.213:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 77.72.169.211:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 5.39.72.109:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 81.187.30.115:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 212.227.67.34:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 212.227.67.33:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 207.38.82.134:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 83.211.9.232:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 212.53.40.43:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
Apparent source IP 74.125.250[.]129 Apparent origin of command packets, assessed as likely spoofed.
Domain stun.l.google.com Legitimate Google STUN service referenced in the analysis; not a confirmed malicious domain.
Attack target 112.151.157[.]222:8080 South Korean ISP endpoint targeted by observed flooding instructions, not attacker infrastructure.
Attack target 192.170.240[.]137:53 University of Chicago cluster endpoint targeted by flooding instructions, not attacker infrastructure.
Attack target 23.81.40[.]193:25565 Minecraft endpoint targeted by flooding instructions, not attacker infrastructure.
Attack target 147.185.221[.]129:25565 Minecraft endpoint targeted by flooding instructions, not attacker infrastructure.
Malware path /usr/local/bin/.cling Hidden malware copy used for persistence.
Malware path /root/.cling Hidden malware copy used for persistence.
File name .cling Malware artifact recommended for host-based hunting.
Persistence file /etc/inittab Startup configuration modified to execute malware copies.
Persistence file /etc/init.d/rcS Initialization script modified for persistence.
Persistence file /etc/rc.d/rc.boot Boot script modified for persistence.
File path /usr/bin/wget.r Preserved original download utility artifact.
File path /usr/bin/wget.p Companion file recording the original utility’s location.
File path /bin/wget.r Preserved original download utility artifact.
File path /bin/wget.p Companion file recording the original utility’s location.
File path /usr/local/bin/wget.r Preserved original download utility artifact.
File path /usr/local/bin/wget.p Companion file recording the original utility’s location.
File path /sbin/wget.r Preserved original download utility artifact.
File path /sbin/wget.p Companion file recording the original utility’s location.
File path /usr/sbin/wget.r Preserved original download utility artifact.
File path /usr/sbin/wget.p Companion file recording the original utility’s location.
File name wget.r Renamed legitimate download utility; suspicious in this replacement pattern.
File name wget.p Companion path-recording file created by the malware.
File name wget Legitimate utility replaced by Cling; its name alone is not malicious.
File name mipsel Payload filename appearing in the source loader URLs.
Component name UDPServer Vulnerable Realtek diagnostic component; exposure context, not proof of infection.
Local port 33957 Port used by the analyzed sample for its single-instance check.
Infection tag realtek.selfrep Argument identifying the initial Realtek exploitation method.
Infection tag selfrep.router Router replication tag shown in the registration-message example.
Detection string .selfrep String included in the source YARA rule.
HTTP header User-Agent: clingwashere Distinctive string included in the source YARA rule.
Detection string /.clingx00 Malware-path string, including its null terminator, from the source YARA rule.
Detection string mount --bind /tmp /proc/%d Command string included in the source YARA rule.
HTTP request string POST /picsdesc.xml Exploit-related request string included in the source YARA rule.
Exploit prefix orf; Prefix of UDP exploitation datagrams described in the report.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Top Fine-Grained Authorization Tools for 2026

Next Post

Top 10 Certificate Lifecycle Management Tools for 2026

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Citrix, FortiMail, and Apple Zero-Days Expose Users
October 5, 2026
South Korean President Orders Full Security Checks After Financial Sector Hacks
October 4, 2026
ShinyHunters Member Arrested, Cooperating with FBI in Jordan
October 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us