Cling Botnet Spoofs Google STUN to Hide Commands — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CVE-2021-35394, a critical CVSS 9.8 RCE flaw in the Realtek Jungle SDK, saw a spike in exploit attempts starting around September 5, 2026, with Nozomi Networks confirming a subset deliver the Cling botnet
- Cling embeds exploit logic for seven additional RCE vulnerabilities across routers and DVRs from Eir, MVPower, LB-LINK, FiberHome/China Mobile, TBK, and Linksys (CVE-2014-8361 through CVE-2025-34037)
- The malware achieves persistence by writing itself to /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot for SysV and BusyBox init systems, or by replacing the system's wget binary with itself
- Cling's C2 channel polls 13 hard-coded public STUN servers every ~5 seconds with all-zero transaction IDs, then encodes operator commands inside STUN transaction ID fields so traffic looks like routine NAT-traversal
- The server at 145.249.115[.]184 returned all-zero transaction IDs in Binding Success Responses, which Nozomi says marks it as a STUN server custom-tailored to relay commands to infected hosts
- Operator-issued commands originate from 74.125.250[.]129—the IP stun.l.google.com resolves to—making malicious replies indistinguishable from legitimate Google STUN traffic, with DoS targets including a South Korean ISP, a University of Chicago cluster, and Minecraft servers
Why it matters: Cling turns STUN, a protocol nearly every NAT-traversal system allows by default, into a hidden C2 channel—and spoofs Google's own STUN IP so defenders can't block-list the source. With seven embedded router/DVR exploits plus worm-like spreading, IoT-heavy enterprises that haven't baseline'd their STUN traffic face a significantly harder detection problem.
Ask SkimNews




