Full Report
Nozomi Networks Labs has identified a botnet dubbed Cling that exploits internet-exposed IoT and networking devices and disguises... The post Cling botnet uses STUN traffic to conceal command-and-control activity and attacks against vulnerable IoT devices appeared first on Industrial Cyber.
Analysis Summary
# Tool/Technique: Cling Botnet
## Overview
Cling is a sophisticated botnet discovered by Nozomi Networks Labs that targets internet-exposed IoT and networking devices. Its primary innovation is the use of the Session Traversal Utilities for NAT (STUN) protocol to mask its Command-and-Control (C2) communications. By disguising malicious traffic as legitimate NAT-traversal activity, Cling evades traditional network security monitoring that typically overlooks STUN traffic generated by common collaboration tools like Zoom or Microsoft Teams.
## Technical Details
- **Type:** Malware family (Botnet)
- **Platform:** IoT and networking devices (MIPS architecture identified; routers, access points, DVRs)
- **Capabilities:** Exploitation of N-day vulnerabilities, STUN-based C2 masking, TCP tunneling, proxying, and Distributed Denial-of-Service (DDoS) attacks.
- **First Seen:** October 2026 (Reported)
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1190 - Exploit Public-Facing Application
- **TA0005 - Defense Evasion**
- T1001.003 - Data Steganography (Encoding commands in STUN Transaction IDs)
- T1564 - Hide Artifacts (Masquerading as legitimate STUN traffic)
- **TA0011 - Command and Control**
- T1071.001 - Application Layer Protocol (STUN/UDP)
- T1572 - Protocol Tunneling
- **TA0040 - Impact**
- T1498.001 - Network Denial of Service: Direct Exploitation (Flooding)
## Functionality
### Core Capabilities
- **Vulnerability Exploitation:** Cling uses a suite of exploits to propagate, specifically targeting:
- **CVE-2021-35394:** Realtek Jungle SDK RCE (Primary vector).
- **CVE-2014-8361:** Realtek SDK RCE.
- **CVE-2023-26801:** LB-LINK routers RCE.
- **CVE-2024-3721:** TBK DVR RCE.
- **CVE-2025-34037:** Linksys RCE.
- **CVE-2016-10372:** Eir D1000 router RCE.
- **CVE-2023-41011:** FiberHome/China Mobile router RCE.
- **CVE-20-16-20016:** MVPower CCTV DVR RCE.
- **Propagation:** Scans for and infects additional vulnerable IoT devices across the internet.
### Advanced Features
- **STUN Masquerading:** The malware uses a hardcoded list of 13 public STUN servers (e.g., `stun.l.google[.]com`).
- **Command Encoding:** It hides operator commands within the 96-bit "Transaction ID" field of STUN packets. This allows the bot to receive instructions while appearing to perform routine network discovery.
- **Attack Modules:** Supports TCP tunneling and proxying, as well as specific DDoS flood modules.
## Indicators of Compromise
- **File Hashes:** (Specific hashes not provided in the summary text, but MIPS samples are identified in Nozomi's research).
- **Network Indicators:**
- `stun.l.google[.]com` (Abused legitimate infrastructure)
- 13 hardcoded public STUN servers (Used for C2 transit)
- Traffic on UDP port 3478 (Standard STUN port)
- **Behavioral Indicators:**
- Outbound STUN requests from IoT devices that do not typically run VoIP or collaboration software.
- High-volume UDP/TCP traffic directed at South Korean and U.S. IP ranges (DDoS activity).
## Associated Threat Actors
- Currently unattributed (Clusters show sophisticated knowledge of IoT exploitation and network protocols).
## Detection Methods
- **Behavioral Detection:** Monitoring for STUN traffic originating from non-standard devices (e.g., industrial gateways, DVRs, or headless IoT sensors).
- **Protocol Analysis:** Inspecting STUN Transaction IDs for non-random or patterned data that may indicate encoded commands.
- **Signature-based detection:** Deploying IDS signatures for the specific RCE exploits listed in the functionality section.
## Mitigation Strategies
- **Patch Management:** Prioritize patching Realtek SDK components and associated router firmware (specifically addressing CVE-2021-35394).
- **Network Segmentation:** Isolate IoT and networking devices from the public internet and limit outbound communication to necessary services only.
- **Egress Filtering:** Block or strictly monitor UDP port 3478 (STUN) for devices that have no legitimate business requirement for NAT traversal protocols.
## Related Tools/Techniques
- **Mirai:** Shares the botnet propagation model but differs significantly in C2 communication methods.
- **STUNner:** General concept of using STUN for covert channels.