Cling Botnet Spoofs Google STUN Traffic to Hide Commands Sent to Infected IoT Devices
Cling IoT botnet hides operator commands in spoofed Google STUN replies while exploiting exposed routers and DVRs.
Nozomi Networks Labs documented Cling, an IoT botnet that hides operator commands inside spoofed Google STUN replies while exploiting exposed routers and DVRs. Propagation centers on CVE-2021-35394 in the Realtek Jungle SDK and also carries exploits for LB-LINK, Linksys, Eir, FiberHome, China Mobile, TBK, and MVPower devices. A analyzed MIPS sample persists through init scripts and a trojanized wget, then supports scanning, TCP tunneling, proxying, and denial-of-service. Operators spoofed stun.l.google.com and issued flood tasks against a South Korean ISP, a University of Chicago cluster, and two Minecraft servers; service disruptions were not independently confirmed, and Google infrastructure was not found compromised.
- Commands occupy the STUN transaction ID and are polled about every five seconds.
- Initial access uses CVE-2021-35394 plus seven other router and DVR flaws.
- Persistence uses hidden .cling binaries, init scripts, and a replaced wget.
- Tasks included propagation and floods; resulting outages were not confirmed.
- Hunt zero transaction IDs, odd STUN registrations, and wget.r artifacts.
Vulnerabilities mentionedAll →
- CVE-2014-8361—100%Improper Input Validation in Realtek SDK miniigd SOAP Service Enables Remote RCEpublished —· Realtek SDK KEV
- CVE-2016-103729.882%The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as…
Full article606 words · extracted from gbhackers.com · click to collapse
Cling, an IoT botnet that disguises operator commands as Google STUN replies, blending malicious communications into routine NAT traversal traffic.
Published October 1, the research documents exploitation of exposed networking devices and a command channel designed to exploit trust in familiar infrastructure.
Researchers discovered the malware while investigating increased exploitation of CVE-2021-35394, a remote code execution vulnerability in the Realtek Jungle SDK diagnostic component, commonly compiled as UDPServer.
Attackers sent UDP payloads beginning with orf;, followed by shell commands that downloaded and executed the bot using BusyBox wget.
Analysis focused primarily on a MIPS sample. Its propagation engine also contains exploits for CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, and CVE-2016-20016, covering Realtek components, LB-LINK, Linksys, Eir, FiberHome and China Mobile routers, and TBK and MVPower DVRs.
Cling copies itself to /root/.cling and /usr/local/bin/.cling, then appends execution entries to /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot.
It also replaces wget with its own executable, preserving the legitimate binary as wget.r and recording its location in wget.p.
Subsequent wget invocations restart the malware while forwarding arguments to the original utility.
STUN helps endpoints discover their public addresses and NAT-mapped ports. Its widespread use in conferencing and browser communications gives Cling a plausible cover for repeated UDP exchanges.
Approximately every five seconds, infected devices send Binding Requests to 13 hardcoded STUN servers.
Unlike compliant implementations, these requests use all-zero transaction IDs. The bot records mapped ports, then sends custom registration datagrams containing those ports and an infection-method tag.
Operator commands occupy the 12-byte STUN transaction ID field, repurposing a normally random identifier into instructions and parameters.
Supported functions include payload execution, scanning and exploitation, TCP tunneling, proxy relaying, and denial-of-service flooding.
Nozomi Networks Labs has identified a botnet, dubbed Cling that exploits internet-exposed IoT and networking devices
Researchers identified 145.249.115[.]184 as operator-controlled or collaborating infrastructure after it returned nonconforming responses.
Cling IoT Botnet
A test client advertised different port sets to each server; commands later reached a port disclosed exclusively to the suspect host.
The distinction matters operationally: most listed STUN servers had clean reputations and appeared in public directories. Their presence in the bot’s configuration does not establish malicious ownership.
Analysts should correlate protocol anomalies with device behavior before treating every contacted endpoint as hostile infrastructure automatically.
Command-bearing packets appeared to originate from 74.125.250[.]129, associated with stun.l.google.com.
Nozomi assessed source-address spoofing as the most likely explanation, supported by consistent TTL differences between genuine STUN responses and command packets.
The findings do not establish that Google infrastructure was compromised.
During several days of monitoring, operators issued propagation tasks and flooding instructions targeting a South Korean ISP, a University of Chicago cluster, and two Minecraft servers.
These observations demonstrate received attack instructions, not independently confirmed service disruptions.
Defenders should inspect STUN semantics rather than rely on IP reputation.
Repeated zero-ID Binding Requests, non-STUN registration payloads reaching STUN endpoints, and unexpected conferencing-like traffic from embedded appliances provide useful hunting signals.
Host investigations should check .cling copies, altered initialization scripts, and wget.r or wget.p artifacts.
Nozomi’s technical report includes indicators, a YARA rule, and ATT&CK mappings for targeted detection engineering.
Organizations should patch affected devices, remove unnecessary internet exposure, restrict inbound access, and segment appliances that cannot be updated.
Cling’s central defensive lesson is that trusted-looking traffic can still carry attacker instructions when protocol fields and source addresses are deliberately manipulated.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.