Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Cling malware is turning compromised internet-connected devices into a botnet while disguising its control traffic as replies from Google’s public STUN service.

The technique makes attacker instructions look like routine communications used by applications to connect across network boundaries.

The infection begins with attacks against exposed devices running vulnerable Realtek software. Earlier reporting on Realtek SDK exploitation attacks documented the same entry point, showing how old flaws continue to give attackers access to routers, access points, repeaters, and other appliances.

Researchers from Nozomi Networks identified Cling while examining a spike in exploitation attempts against CVE-2021-35394.

Nozomi Networks said in a report shared with Cyber Security News (CSN) that the malware uses legitimate-looking STUN exchanges to register infected devices and receive operator commands.

Published on October 1, 2026, the analysis describes a botnet capable of spreading, relaying traffic, opening tunnels, and launching denial-of-service attacks.

Exploit payloads embedded in the sample (Source - Nozomi Networks)
Exploit payloads embedded in the sample (Source – Nozomi Networks)

Researchers observed attack instructions targeting an internet provider, university infrastructure, and gaming services, but did not report a total infection count or confirmed outages.

Cling Malware Masquerades as Google STUN Traffic

STUN helps a device discover its public address and the network port assigned by its router. Video meetings and browser communications commonly use it, creating background traffic that attackers can imitate without immediately attracting attention from security teams.

Cling contacts 13 hardcoded STUN servers roughly every five seconds. It gathers the ports returned by those services, then sends a separate registration message containing the mapped ports and a tag identifying how the device was infected.

Those registration messages are not valid STUN traffic, and normal servers ignored them during testing. However, one server returned an unusual response that did not correctly echo a request identifier, prompting researchers to investigate its relationship with the botnet.

The team advertised different port sets to each server while pretending to register an infected device. Several hours later, commands arrived at ports disclosed only to the suspicious server, demonstrating that its registration traffic was reaching the operator.

Commands occupy the protocol’s 12-byte transaction identifier, a field normally used to match requests with replies.

This camouflage recalls browser-based malware command channels that similarly exploit familiar communication patterns, although Cling operates through UDP rather than a hijacked browser.

init persistence setup (Source - Nozomi Networks)
init persistence setup (Source – Nozomi Networks)

The command packets appeared to originate from Google’s STUN infrastructure. Researchers assessed source-address spoofing as the most likely explanation, supported by differences in packet lifetime values.

They did not establish that Google’s servers were compromised or actually sending the instructions. The distinction matters for investigations: most listed STUN endpoints are legitimate public services, not confirmed attacker infrastructure. Their presence in traffic should be assessed alongside protocol anomalies and device behavior.

Persistence and Defense

Initial exploitation allows attackers to issue shell commands that download and execute the malware. The analyzed sample also contains exploits for CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, and CVE-2016-20016, extending its reach across routers and video-recording equipment.

After infection, Cling creates hidden copies and adds startup entries to survive reboots. It also replaces a standard download utility while preserving access to the original program, allowing ordinary maintenance tasks or later downloads to trigger the malware again.

Its operators can download additional payloads, start or stop scanning, establish TCP tunnels, enable proxy relays, and order flooding attacks. Comparable PolarEdge IoT proxy operations illustrate why compromised edge devices can become infrastructure for abuse beyond the original intrusion.

The analysis examined a MIPS sample, with supporting observations from related files. Its persistence and command features should be treated as findings about the examined sample, not every variant.

Nozomi recommends reviewing exposed appliances, patching the exploited vulnerabilities, and restricting inbound access where updates are unavailable.

Network segmentation can reduce exposure, while investigators should inspect startup changes and replaced download utilities for the artifacts listed below.

Defenders should also investigate frequent STUN requests with all-zero transaction identifiers, unexpected UDP registration messages, and connections that depart from a device’s normal behavior. Trusted server reputation alone cannot establish safety when attackers can forge the apparent source of command traffic.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-1 3b0ac6aaabb3bf8058ca14f9c8ccc613cfa3ea71 Primary MIPS sample analyzed by researchers.
SHA-1 08636d09d9ffd1713bd6bcb965ad40b6ce3de1aa Additional MIPS sample listed in the report.
SHA-256 90d738a8d650e3fefda9d7efa4baa11bd89ab05fcf0eb173e04aa01a52b465e2 Sample hash included in the source YARA rule metadata.
SHA-256 3a6927a3399f2a10bb2e2229482e5096e5f1c3401a87f7f1730db11243531e28 Second sample hash included in the source YARA rule metadata.
Loader URL hxxp://118.45.196[.]225:800/mipsel Malware loader location listed in the source.
Loader URL hxxp://120.193.219[.]210:800/mipsel Malware loader location listed in the source.
Loader URL hxxp://58.211.144[.]243:800/mipsel Malware loader location listed in the source.
Loader endpoint 121[.]32.243.81:1337 Loader specified in an observed scan-and-exploit command.
IP address 145.249.115[.]184 STUN server linked to operator access through controlled registration testing.
STUN endpoint 74.125.250.129:19302 Public Google STUN endpoint contacted by Cling; not established as compromised.
STUN endpoint 145.249.115.184:3478 Hardcoded endpoint associated with the suspicious STUN server.
STUN endpoint 216.93.246.18:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 85.17.88.164:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 77.72.169.213:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 77.72.169.211:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 5.39.72.109:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 81.187.30.115:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 212.227.67.34:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 212.227.67.33:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 207.38.82.134:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 83.211.9.232:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
STUN endpoint 212.53.40.43:3478 Hardcoded STUN endpoint; inclusion does not establish malicious ownership.
Apparent source IP 74.125.250[.]129 Apparent origin of command packets, assessed as likely spoofed.
Domain stun.l.google.com Legitimate Google STUN service referenced in the analysis; not a confirmed malicious domain.
Attack target 112.151.157[.]222:8080 South Korean ISP endpoint targeted by observed flooding instructions, not attacker infrastructure.
Attack target 192.170.240[.]137:53 University of Chicago cluster endpoint targeted by flooding instructions, not attacker infrastructure.
Attack target 23.81.40[.]193:25565 Minecraft endpoint targeted by flooding instructions, not attacker infrastructure.
Attack target 147.185.221[.]129:25565 Minecraft endpoint targeted by flooding instructions, not attacker infrastructure.
Malware path /usr/local/bin/.cling Hidden malware copy used for persistence.
Malware path /root/.cling Hidden malware copy used for persistence.
File name .cling Malware artifact recommended for host-based hunting.
Persistence file /etc/inittab Startup configuration modified to execute malware copies.
Persistence file /etc/init.d/rcS Initialization script modified for persistence.
Persistence file /etc/rc.d/rc.boot Boot script modified for persistence.
File path /usr/bin/wget.r Preserved original download utility artifact.
File path /usr/bin/wget.p Companion file recording the original utility’s location.
File path /bin/wget.r Preserved original download utility artifact.
File path /bin/wget.p Companion file recording the original utility’s location.
File path /usr/local/bin/wget.r Preserved original download utility artifact.
File path /usr/local/bin/wget.p Companion file recording the original utility’s location.
File path /sbin/wget.r Preserved original download utility artifact.
File path /sbin/wget.p Companion file recording the original utility’s location.
File path /usr/sbin/wget.r Preserved original download utility artifact.
File path /usr/sbin/wget.p Companion file recording the original utility’s location.
File name wget.r Renamed legitimate download utility; suspicious in this replacement pattern.
File name wget.p Companion path-recording file created by the malware.
File name wget Legitimate utility replaced by Cling; its name alone is not malicious.
File name mipsel Payload filename appearing in the source loader URLs.
Component name UDPServer Vulnerable Realtek diagnostic component; exposure context, not proof of infection.
Local port 33957 Port used by the analyzed sample for its single-instance check.
Infection tag realtek.selfrep Argument identifying the initial Realtek exploitation method.
Infection tag selfrep.router Router replication tag shown in the registration-message example.
Detection string .selfrep String included in the source YARA rule.
HTTP header User-Agent: clingwashere Distinctive string included in the source YARA rule.
Detection string /.clingx00 Malware-path string, including its null terminator, from the source YARA rule.
Detection string mount --bind /tmp /proc/%d Command string included in the source YARA rule.
HTTP request string POST /picsdesc.xml Exploit-related request string included in the source YARA rule.
Exploit prefix orf; Prefix of UDP exploitation datagrams described in the report.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices appeared first on Cyber Security News.