Full Report
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report
Analysis Summary
# Tool/Technique: Cling Botnet
## Overview
Cling is a sophisticated botnet malware primarily targeting IoT devices, routers, and DVRs. Its most distinguishing feature is the repurposing of Session Traversal Utilities for NAT (STUN) traffic for its command-and-control (C2) infrastructure. By masquerading as legitimate NAT-traversal activity, Cling evades traditional network monitoring and security controls.
## Technical Details
- **Type:** Malware Family (Botnet)
- **Platform:** Linux-based IoT devices (routers, DVRs, NVRs), specifically those using Realtek SDKs, SysV, or BusyBox init systems.
- **Capabilities:** Propagation (self-replication), Proxying, Tunneling, Distributed Denial-of-Service (DDoS), and Persistence.
- **First Seen:** September 5, 2026 (Spike in activity observed by Nozomi Networks).
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1190 - Exploit Public-Facing Application] (Exploiting vulnerabilities in Realtek SDK and other router firmware).
- **[TA0003 - Persistence]**
- [T1543.002 - Create or Modify System Process: Systemd Service] (Targeting /etc/inittab and init.d scripts).
- [T1574.006 - Hijack Execution Flow: LD_PRELOAD / Path Hijacking] (Replacing legitimate `wget` binary).
- **[TA0011 - Command and Control]**
- [T1102 - Web Service] (Abusing public STUN infrastructure).
- [T1001.003 - Data Obfuscation: Protocol Impersonation] (Mimicking STUN traffic).
- **[TA0005 - Defense Evasion]**
- [T1564.001 - Hide Artifacts: Hidden Files and Directories] (Storing files in `.cling`).
## Functionality
### Core Capabilities
- **Multi-Vulnerability Exploitation:** Includes a built-in library of exploits for various RCE vulnerabilities (CVE-2021-35394, CVE-2014-8361, CVE-2023-26801, etc.) to facilitate lateral movement and propagation.
- **Persistence:** Achieving longevity by appending itself to system startup scripts (`/etc/inittab`, `/etc/init.d/rcS`, etc.) and replacing the legitimate `wget` binary with a malicious version.
- **Single Instance Locking:** Binds a socket to port `33957` using `SO_REUSEADDR` to ensure only one instance of the malware runs at a time.
### Advanced Features
- **STUN-Based C2:** The malware sends STUN Binding Requests to a hardcoded list of 13 servers. It uses a non-standard "all-zero" Transaction ID to signal its presence and polls for commands within the STUN Transaction ID field of returning packets.
- **Traffic Camouflage:** Because STUN is common in VoIP and peer-to-peer applications, the malicious traffic blends in with normal network noise, making it difficult to identify without deep packet inspection.
- **Infection Tagging:** During registration, Cling sends a UDP datagram containing a tag (e.g., `realtek.selfrep`) to notify the operator of which exploit was successful.
## Indicators of Compromise
- **File Names:**
- `/root/.cling`
- `/usr/local/bin/.cling`
- **Network Indicators:**
- C2 IP: `145.249.115[.]184`
- Target Port: `UDP/3478` (Standard STUN port)
- Locking Port: `33957`
- **Behavioral Indicators:**
- Modification of `/etc/inittab` or `/etc/init.d/rcS`.
- Legitimate `wget` binary moved or replaced.
- Periodic UDP traffic to public STUN servers with an unusual "all-zero" Transaction ID.
## Associated Threat Actors
- **Unknown:** Currently attributed to generalized botnet operators targeting unpatched IoT devices.
## Detection Methods
- **Signature-based:** Search for the hidden file string `.cling` and the presence of the malware's specific exploit payloads in network traffic.
- **Behavioral Detection:** Monitor for modifications to system initialization files on IoT devices.
- **Network Analysis:** Inspect STUN traffic (UDP 3478) for RFC non-compliant packets, specifically those utilizing static or all-zero Transaction IDs.
## Mitigation Strategies
- **Patch Management:** Immediately apply patches for the Realtek Jungle SDK (CVE-2021-35394) and other listed CVEs.
- **Network Segmentation:** Isolate IoT devices and DVRs from critical management networks.
- **Egress Filtering:** Restrict outbound UDP traffic from IoT devices to only necessary services; monitor or block traffic to unknown public STUN servers.
- **Hardening:** Disable unused services (like Telnet/HTTP management) on public-facing routers.
## Related Tools/Techniques
- **Mirai/Gafgyt:** Similar in propagation methods but differ in C2 implementation.
- **STUN-based C2:** A technique also observed in the "LetsCall" vishing malware.