Breaking
Cyber CrimeConfirmed

Cling Botnet Hides Commands in STUN Traffic

New botnet abuses common STUN protocol and public servers to blend command-and-control with legitimate NAT-traversal activity.

··59 minutes ago·7 min read
a close up of a network with wires connected to it
Photo by Albert Stoynov on Unsplash

A botnet that blends its command-and-control traffic into routine network address translation activity is being deployed through exploit attempts against a patched Realtek SDK flaw. Nozomi Networks, which analyzed the malware, said the activity uses ordinary STUN behavior to make malicious commands look like legitimate NAT-traversal traffic rather than a new propagation trick.

The operational technology security company observed a spike in attempts to exploit CVE-2021-35394 (CVSS score: 9.8), a critical remote code execution flaw in the Realtek Jungle SDK, starting around September 5, 2026. A subset of that activity delivered a botnet the company calls Cling.

Exploit Logic for Routers and DVRs

According to Nozomi Networks, the Cling sample embeds exploit logic for a range of command injection and remote code execution vulnerabilities affecting routers and DVRs from multiple vendors. The sample's built-in arsenal includes flaws in Realtek SDK, Eir D1000 routers, MVPower CCTV DVRs, LB-LINK routers, FiberHome SR1041F routers and China Mobile HG6543C4 devices, TBK DVRs, and Linksys routers.

The malware's ability to carry multiple exploits means a single sample can attempt to compromise different classes of internet-facing devices without needing a separate payload for each target type. That approach is common among IoT-focused botnets, which often chain vulnerabilities to maximize the number of devices they can recruit.

Persistence on SysV and BusyBox Systems

Once it gains a foothold, Cling takes steps to ensure only one instance of the malware runs on an infected device. Nozomi Networks described the single-instance check as binding a socket with SO_REUSEADDR to port 33957 and exiting cleanly if the bind fails. The sample then copies itself to /root/.cling and /usr/local/bin/.cling.

Both executables are appended to /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot, achieving persistence on SysV and BusyBox init systems. The report also describes an alternative persistence mechanism in which the malware locates the wget binary on the infected system and replaces it with the malware after moving the original to another location. That causes the malware to execute whenever a legitimate process invokes the wget command.

STUN Servers as a Control Channel

The most distinctive element of Cling is its use of STUN traffic and public STUN infrastructure to register infected hosts, receive operator commands, and make malicious activity less obvious to network monitoring. STUN, short for Session Traversal Utilities for Network Address Translation, is a standardized protocol designed to help devices behind a NAT or firewall establish peer-to-peer real-time communications.

The malware follows a four-step process for command-and-control communications, according to Nozomi Networks. First, it sends a STUN Binding Request to a hard-coded list of 13 STUN servers roughly every 5 seconds, with the transaction ID set to all zeros instead of a random value as the specification requires. Second, it records the externally observed ports returned by those servers when they respond with a Binding Success Response containing the public IP address of the endpoint and the associated port numbers. Third, it sends a custom registration message, a UDP datagram, to each server that includes the mapped ports and a tag denoting how the device was infected, such as realtek.selfrep or selfrep.router. Fourth, it polls for UDP packets that encode operator commands in the STUN transaction ID field.

"From a network monitoring perspective, the activity appears as innocuous interaction with STUN servers," Nozomi Networks said. "Given that the custom registration message is sent to every STUN server in the list, it is apparent that the operator requires visibility into at least one of the servers, in order to track new bots joining the swarm to know where to send commands to."

— Nozomi Networks, the operational technology security company that published the analysis

The registration messages do not conform to the STUN protocol definition, causing legitimate STUN servers to drop the packet. However, one of the 13 servers, 145.249.115[.]184, returned an all-zero transaction ID instead of echoing the transaction ID of the original Binding Request in its Binding Success Response.

Nozomi Networks said that unusual behavior suggests the STUN server is tailored to the bot's own STUN traffic and is used to send operator-issued commands to the infected device by embedding those commands in the STUN transaction ID field.

Commands That Scan, Tunnel, and Flood

The commands available through this channel let the operator recursively scan and spread the botnet in a worm-like fashion, spawn or stop a TCP tunnel, launch or stop a proxy, and perform a denial-of-service attack against a specified target for a given duration. Nozomi Networks listed several targets of the flooding attacks: 112.151.157[.]222:8080, described as a South Korean ISP; 192.170.240[.]137:53, described as a University of Chicago cluster; and two Minecraft-related addresses, 23.81.40[.]193:25565 and 147.185.221[.]129:25565.

The mix of targets indicates the botnet is not limited to one victim profile. The listed IP addresses range from an ISP and a university cluster to Minecraft servers, which are frequently targeted by denial-of-service attacks.

The Command Source That Looks Familiar

Nozomi Networks also examined where the C2 traffic appeared to originate. The packets carrying operator commands came from 74.125.250[.]129, an IP address that stun.l.google.com resolves to.

"The most interesting part of the C2 traffic is where the commands appeared to come from," Nozomi Networks explained. "The packets carrying operator commands originate from 74.125.250[.]129, an IP address that stun.l.google.com resolves to."

— Nozomi Networks, the operational technology security company that published the analysis

"In other words, the operator is not merely hiding commands inside a STUN-looking packet, but they are making those commands appear as if they are legitimate replies from one of the most recognizable STUN services on the internet."

— Nozomi Networks, the operational technology security company that published the analysis

Nozomi Networks described Cling as notable not because it introduces a new propagation technique but because it repurposes ordinary STUN behavior into a practical C2 channel, producing a botnet whose traffic can resemble legitimate NAT-traversal activity while still supporting propagation, proxying, tunneling, and denial-of-service commands.

A Patch That Did Not End the Activity

Nozomi Networks linked the malware delivery to attempted exploitation of CVE-2021-35394, a critical remote code execution flaw in the Realtek Jungle SDK. The vulnerability carries a CVSS score of 9.8. The spike in exploitation attempts observed around September 5, 2026, shows that devices still running vulnerable firmware remain reachable and attractive to operators, even after a fix has been available.

The Cling sample's bundled exploits cover several older flaws as well. CVE-2014-8361 is a Realtek SDK RCE, and CVE-2016-10372 is an Eir D1000 router RCE. The others include MVPower CCTV DVR RCE (CVE-2016-20016), LB-LINK routers RCE (CVE-2023-26801), FiberHome SR1041F router / China Mobile HG6543C4 RCE (CVE-2023-41011), TBK DVR RCE (CVE-2024-3721), and Linksys RCE (CVE-2025-34037).

The presence of older CVE identifiers in the sample's exploit set reflects the reality that many routers and DVRs remain unpatched for long periods, giving operators a broad pool of potential recruits for a botnet.

Why the STUN Disguise Matters

The use of STUN as a C2 carrier is the element Nozomi Networks emphasized most. Because STUN is a standard protocol for NAT traversal, packets that follow its general shape are more likely to pass through network monitoring without raising alarms. The malware's registration messages do not strictly conform to STUN, causing legitimate servers to drop them, but the traffic still looks like routine NAT-traversal activity to many observers.

One server in the hard-coded list behaved differently. The server at 145.249.115[.]184 returned an all-zero transaction ID instead of echoing the original transaction ID, which Nozomi Networks said indicates it is tailored to the bot's traffic and used to relay operator commands through the STUN transaction ID field.

The command packets that reached the infected device came from 74.125.250[.]129, an address that stun.l.google.com resolves to. By making commands appear to come from a widely recognized STUN service, the operator adds a layer of apparent legitimacy to traffic that is otherwise malicious.

What the Botnet Can Do Once Embedded

The operator commands supported by Cling give the botnet several capabilities beyond simple infection. Recursive scanning lets it spread like a worm to other reachable devices. A TCP tunnel and a proxy mode provide ways to relay traffic through the infected host. A denial-of-service mode lets the operator flood a chosen target for a set period.

Several of the listed flooding targets point to Minecraft servers, while others point to a South Korean ISP and a University of Chicago cluster. The variety of targets suggests the botnet is positioned for both volumetric attacks and use as a general-purpose foothold on compromised devices.

The single-instance check on port 33957 and the wget replacement trick both serve to keep the malware resident and difficult to dislodge on systems with limited management interfaces. The malware's copies in /root/.cling and /usr/local/bin/.cling, along with entries in /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot, are designed to survive reboots on SysV and BusyBox init systems.

The Takeaway for Defenders

The Cling analysis suggests that defenders who rely on traffic category alone could miss command-and-control activity that mimics STUN. Because the malware sends Binding Requests roughly every 5 seconds and registers with every server in its list of 13, network monitoring that treats all STUN traffic as benign may not flag the pattern. This could mean that detection efforts need to look at STUN transaction ID behavior, including the all-zero value the malware uses, rather than only at the protocol label.

The exploit set bundled into Cling also suggests that unpatched routers and DVRs remain a durable source of recruits for IoT botnets. The activity tied to CVE-2021-35394 around September 5, 2026, indicates that attempted exploitation continues even where a patch exists. For operators of affected device classes, the practical implication is that firmware updates and reduction of exposed management interfaces could shrink the pool of devices a botnet like Cling can add to its swarm.

#botnet#malware#iot security#stun#cve-2021-35394#command-and-control

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories