התרגום נמצא בהכנה. חלק מהטקסטים עדיין מוצגים באנגלית.
Nozomi Networks Labs identifies a new botnet leveraging STUN protocol for command-and-control operations, highlighting risks across IoT and networking infrastructure.

Nozomi Networks Labs has uncovered a sophisticated botnet named Cling that exploits internet-exposed IoT devices by disguising its command-and-control (C2) traffic as legitimate STUN (Session Traversal Utilities for NAT) activity. This method allows the malware to blend into normal network behavior, making it harder to detect. The botnet leverages a range of known vulnerabilities in networking equipment and IoT devices, including several remote code execution (RCE) flaws affecting routers, access points, and digital video recorders.

Exploitation of Realtek Jungle SDK Vulnerability

The primary exploit used by the Cling botnet is CVE-2021-35394, a remote code execution flaw in the Realtek Jungle SDK diagnostic component. This vulnerability, which remains widely abused despite being several years old, affects numerous IoT and networking devices such as routers, access points, repeaters, and other embedded appliances. These devices often lack regular updates, leaving them vulnerable for extended periods.

STUN-Based C2 Traffic Mimics Legitimate NAT Traversal

Cling's command-and-control design mimics STUN-like exchanges, which are commonly used in protocols such as ICE (Interactive Connectivity Establishment), TURN, SIP, and real-time communication applications. The malware encodes commands within STUN transaction IDs, making the traffic appear indistinguishable from routine NAT traversal activity generated by collaboration tools like Microsoft Teams or Zoom.

Exploitation of Multiple Vulnerabilities

In addition to CVE-2021-35394, Cling also exploits several other command-injection vulnerabilities affecting a wide range of networking and IoT devices. These include:

  • CVE-2014-8361 – Realtek SDK RCE
  • CVE-2023-26801 – LB-LINK routers RCE
  • CVE-2024-3721 – TBK DVR RCE
  • CVE-2025-34037 – Linksys RCE
  • CVE-2016-10372 – Eir D1000 router RCE
  • CVE-2023-41011 – FiberHome SR1041F and China Mobile HG6543C4 RCE
  • CVE-2016-20016 – MVPower CCTV DVR RCE

Malware Communication via STUN Servers

The botnet communicates with its operators through a hardcoded list of 13 public STUN servers, most of which have clean reputations and appear on public lists. These servers are used to register infected devices and receive commands from the operator. The malware sends custom registration messages that reveal how the device was infected and provide the operator with contact details.

Detection Challenges and Mitigation Recommendations

Because the communication resembles legitimate NAT traversal traffic, detecting Cling requires identifying anomalies in network behavior. Nozomi recommends defenders monitor for repeated STUN Binding Requests sent at short intervals with all-zero transaction IDs or non-STUN UDP datagrams sent to STUN endpoints. Assets should also be monitored for unexpected connections that deviate from the established baseline.

Operational and Technical Implications for Security Integrators

Cling’s use of STUN traffic highlights the need for network-level monitoring, especially in environments where host telemetry is limited. Defenders should check for compromised-device artifacts such as malware copies named .cling, persistence entries added to init scripts, and replaced wget binaries with companion files like wget.r and wget.p.

Broader Industry Implications

Nozomi’s research also noted that the Cling botnet represents a shift in how commodity IoT botnets are evolving. While still spreading through exposed devices, its use of STUN-based C2 traffic makes it distinct from earlier Mirai-like botnets. The findings underscore the importance of patching and exposure reduction for internet-facing devices, as well as combining protocol-aware inspection with behavioral baselining to detect suspicious deviations in otherwise normal traffic.