Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
Cling botnet malware disguises its commands as Google STUN traffic on compromised IoT devices.
Nozomi Networks analyzed Cling, a MIPS IoT botnet that registers compromised devices and receives commands while imitating Google’s public STUN service over UDP. Infections begin on exposed appliances, including a spike in attempts against Realtek CVE-2021-35394; the examined sample also contains exploits for CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, and CVE-2016-20016. After persisting through hidden copies and startup entries, it can download payloads, scan, open TCP tunnels, relay proxy traffic, and launch denial-of-service floods. Commands were observed aimed at an internet provider, university infrastructure, and gaming services, but no infection count or confirmed outages were reported. Researchers judged the apparent Google source addresses most likely spoofed and did not find Google’s STUN servers compromised.