Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
Cling, a new IoT botnet, hides command-and-control in spoofed Google STUN traffic while exploiting Realtek CVE-2021-35394.
Nozomi Networks Labs identified Cling, a MIPS IoT botnet that hides command-and-control inside STUN Binding Requests, including packets spoofed to look like Google STUN traffic. Operators exploit CVE-2021-35394, a critical unauthenticated remote code execution flaw in Realtek Jungle SDK 2.0 through 3.4.14B, then spread to LB-LINK, Linksys, FiberHome, Eir, TBK, and MVPower devices. The malware persists through init scripts and by replacing wget, and can scan, tunnel, proxy, and launch denial-of-service floods. Researchers tied a suspected operator server to 145.249.115.184 and published sample hashes and loader URLs.