Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
Cling botnet malware disguises its commands as Google STUN traffic on compromised IoT devices.
Nozomi Networks analyzed Cling, a MIPS IoT botnet that registers compromised devices and receives commands while imitating Google’s public STUN service over UDP. Infections begin on exposed appliances, including a spike in attempts against Realtek CVE-2021-35394; the examined sample also contains exploits for CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, and CVE-2016-20016. After persisting through hidden copies and startup entries, it can download payloads, scan, open TCP tunnels, relay proxy traffic, and launch denial-of-service floods. Commands were observed aimed at an internet provider, university infrastructure, and gaming services, but no infection count or confirmed outages were reported. Researchers judged the apparent Google source addresses most likely spoofed and did not find Google’s STUN servers compromised.
- Cling hides operator commands in UDP traffic that looks like Google STUN.
- Initial access uses exposed Realtek SDK and other router and NVR flaws.
- Operators can scan, tunnel, proxy, and launch flood attacks.
- Researchers assessed spoofed sources, not a compromise of Google.
- No infection total or confirmed outages were reported.
Vulnerabilities mentionedAll →
- CVE-2014-8361—100%Improper Input Validation in Realtek SDK miniigd SOAP Service Enables Remote RCEpublished —· Realtek SDK KEV
- CVE-2016-103729.882%The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as…
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 145.249.115.184 | ted by Cling; not established as compromised. STUN endpoint 145.249.115.184:3478 Hardcoded endpoint associated with the suspicious STUN |
| ipv4 | 207.38.82.134 | usion does not establish malicious ownership. STUN endpoint 207.38.82.134:3478 Hardcoded STUN endpoint; inclusion does not establish |
| ipv4 | 212.227.67.33 | usion does not establish malicious ownership. STUN endpoint 212.227.67.33:3478 Hardcoded STUN endpoint; inclusion does not establish |
| ipv4 | 212.227.67.34 | usion does not establish malicious ownership. STUN endpoint 212.227.67.34:3478 Hardcoded STUN endpoint; inclusion does not establish |
| ipv4 | 212.53.40.43 | usion does not establish malicious ownership. STUN endpoint 212.53.40.43:3478 Hardcoded STUN endpoint; inclusion does not establish |
| ipv4 | 216.93.246.18 | t associated with the suspicious STUN server. STUN endpoint 216.93.246.18:3478 Hardcoded STUN endpoint; inclusion does not establish |
| ipv4 |
Full article1,424 words · extracted from cybersecuritynews.com · click to collapse
Cling malware is turning compromised internet-connected devices into a botnet while disguising its control traffic as replies from Google’s public STUN service.
The technique makes attacker instructions look like routine communications used by applications to connect across network boundaries.
The infection begins with attacks against exposed devices running vulnerable Realtek software. Earlier reporting on Realtek SDK exploitation attacks documented the same entry point, showing how old flaws continue to give attackers access to routers, access points, repeaters, and other appliances.
Researchers from Nozomi Networks identified Cling while examining a spike in exploitation attempts against CVE-2021-35394.
Nozomi Networks said in a report shared with Cyber Security News (CSN) that the malware uses legitimate-looking STUN exchanges to register infected devices and receive operator commands.
Published on October 1, 2026, the analysis describes a botnet capable of spreading, relaying traffic, opening tunnels, and launching denial-of-service attacks.
.webp)
Researchers observed attack instructions targeting an internet provider, university infrastructure, and gaming services, but did not report a total infection count or confirmed outages.
Cling Malware Masquerades as Google STUN Traffic
STUN helps a device discover its public address and the network port assigned by its router. Video meetings and browser communications commonly use it, creating background traffic that attackers can imitate without immediately attracting attention from security teams.
Cling contacts 13 hardcoded STUN servers roughly every five seconds. It gathers the ports returned by those services, then sends a separate registration message containing the mapped ports and a tag identifying how the device was infected.
Those registration messages are not valid STUN traffic, and normal servers ignored them during testing. However, one server returned an unusual response that did not correctly echo a request identifier, prompting researchers to investigate its relationship with the botnet.
The team advertised different port sets to each server while pretending to register an infected device. Several hours later, commands arrived at ports disclosed only to the suspicious server, demonstrating that its registration traffic was reaching the operator.
Commands occupy the protocol’s 12-byte transaction identifier, a field normally used to match requests with replies.
This camouflage recalls browser-based malware command channels that similarly exploit familiar communication patterns, although Cling operates through UDP rather than a hijacked browser.
.webp)
The command packets appeared to originate from Google’s STUN infrastructure. Researchers assessed source-address spoofing as the most likely explanation, supported by differences in packet lifetime values.
They did not establish that Google’s servers were compromised or actually sending the instructions. The distinction matters for investigations: most listed STUN endpoints are legitimate public services, not confirmed attacker infrastructure. Their presence in traffic should be assessed alongside protocol anomalies and device behavior.
Persistence and Defense
Initial exploitation allows attackers to issue shell commands that download and execute the malware. The analyzed sample also contains exploits for CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, and CVE-2016-20016, extending its reach across routers and video-recording equipment.
After infection, Cling creates hidden copies and adds startup entries to survive reboots. It also replaces a standard download utility while preserving access to the original program, allowing ordinary maintenance tasks or later downloads to trigger the malware again.
Its operators can download additional payloads, start or stop scanning, establish TCP tunnels, enable proxy relays, and order flooding attacks. Comparable PolarEdge IoT proxy operations illustrate why compromised edge devices can become infrastructure for abuse beyond the original intrusion.
The analysis examined a MIPS sample, with supporting observations from related files. Its persistence and command features should be treated as findings about the examined sample, not every variant.
Nozomi recommends reviewing exposed appliances, patching the exploited vulnerabilities, and restricting inbound access where updates are unavailable.
Network segmentation can reduce exposure, while investigators should inspect startup changes and replaced download utilities for the artifacts listed below.
Defenders should also investigate frequent STUN requests with all-zero transaction identifiers, unexpected UDP registration messages, and connections that depart from a device’s normal behavior. Trusted server reputation alone cannot establish safety when attackers can forge the apparent source of command traffic.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.