Cling Botnet Spoofs Google STUN Traffic to Hide Commands Sent to Infected IoT Devices
Cling IoT botnet hides operator commands in spoofed Google STUN replies while exploiting exposed routers and DVRs.
Nozomi Networks Labs documented Cling, an IoT botnet that hides operator commands inside spoofed Google STUN replies while exploiting exposed routers and DVRs. Propagation centers on CVE-2021-35394 in the Realtek Jungle SDK and also carries exploits for LB-LINK, Linksys, Eir, FiberHome, China Mobile, TBK, and MVPower devices. A analyzed MIPS sample persists through init scripts and a trojanized wget, then supports scanning, TCP tunneling, proxying, and denial-of-service. Operators spoofed stun.l.google.com and issued flood tasks against a South Korean ISP, a University of Chicago cluster, and two Minecraft servers; service disruptions were not independently confirmed, and Google infrastructure was not found compromised.