ClingSTUN Profile: IoT Botnet Hides Command-and-Control in STUN Traffic

ClingSTUN is a Linux backdoor and botnet that targets routers, DVRs and IoT devices still exposed on the Internet. Noteworthy is not the new intrusion, but the malware that turns the popular stun protocol in WebRTC, voice, and online meetings into a disguised layer for control communications.

STUN server test results from the ClingSTUN botnet analysis
Analysis of responses from 13 STUN servers found one server returning an abnormal transaction ID. Image: Nozomi Networks Labs

From a 2021 Vulnerability to a New Exploitation Wave

Nozomi Networks Labs says it recorded the number of exploits CVE-2021-35394 increased sharply from about 9/5/2026. This is a remote code execution vulnerability in the UDPServer component of Realtek Jungle SDK, rated 9.8/10 according to CVSS. This component has been integrated into many routers, access points, repeaters, and embedded devices from many manufacturers.

The vulnerability has been patched for a long time, but IoT devices are often rarely inventoried, difficult to upgrade, or have reached the end of their support lifecycle. It is that latency that helps an old technique continue to create an effective entry point. In a portion of the observed traffic, the attacker downloaded a different malware pattern than the regular Mirai variants; Nozomi named it Cling, and FortiGuard Labs called ClingSTUN.

The Campaign Expands Across Multiple Downloader Generations

The October 5 FortiGuard Labs report describes the campaign going through at least three stages with different download servers. Initially, the agent exploited CVE-2022-36553 on Hytec Inter routers; at later stages, they expanded to the vulnerability on EnGenius, D-Link, Realtek, TP-Link, AVTECH, Tenda, Ivanti and many other embedded platforms.

Variant-loaded shell scripts are suitable for a variety of Linux architectures, including arm, x86, MIPS, and PowerPC. Supporting multiple architectures shows that the goal is not a single device model, but a fragmented IoT and network device ecosystem, where legacy firmware can last for years.

How Does ClingSTUN Persist and Eliminate Rivals?

After running, the malware checks to maintain only one copy, then copies itself into /root/.cling and /usr/local/bin/.cling. It fixes startup files like /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot to rerun itself after the device starts up.

A variation also replaces the program wget by malicious code, and at the same time transfer the valid version to another location. When the administration task or another process calls wget, ClingSTUN can be reactivated before forwarding the parameter to the real program. Fortinet also recorded the act of disabling the watchdog, ending the competition process and hiding the progress information with PID-like data 1.

STUN Becomes a Disguised Tunnel for C2

Stun, which stands for Session Traversal Utilities for NAT, gives the device behind NAT a public IP address and a mapped port. This protocol appears frequently in Microsoft Teams, Zoom, Webex, SIP, and WebRTC applications, so stun traffic is generally not considered abnormal.

ClingSTUN sends a Binding Request approximately every five seconds to a public stun server list, records the external port, and then sends a custom subscription containing the infection method. The bot then waits for the encrypted command in the transaction ID field which is 12 bytes long. Nozomi noticed that the transaction ID of the request was set to zero instead of the random value according to RFC 8489 — a signal that can be used for hunting.

Why Can the Traffic Appear to Come from Google?

In a controlled test, Nozomi found that one of the 13 servers did not respond to the transaction ID correctly. When the team registered separate port sets, commands then appeared on suspicious server portals, reinforcing the hypothesis that the infrastructure was involved in coordinating the botnet.

More notably, some command packages have the same source address stun.l.google.com∙ The researchers assessed the most likely explanation to be spoofing the source IP address over a network that does not implement full source authentication, not the controlled Google stun service. This conclusion is supported by the stable difference in TTL between the valid response and the command packet.

From Infected Device to Proxy, Tunnel, and DDoS Tool

ClingSTUN's instruction set allows loading and executing payloads, scanning the Internet for self-propagation, opening or closing TCP tunnels, operating relay proxies, and launching denial-of-service attacks. Nozomi observed the botnet extension scan and flood requests targeting ISP infrastructure, university server clusters, and game servers.

That turns a seemingly low-value router or camera into a proxy node that can hide the source of an attack, the springboard, or the component of a DDoS network. Device owners may not see obvious damage, while their IP addresses are abused and malicious traffic mixed with valid activity.

Technical Risks and the IoT Governance Gap

The case shows that the reputation of an IP address or the validity of a protocol is not sufficient to conclude safe traffic. If the monitoring system only allows stun by service name, ClingSTUN may take advantage of that trust zone. Conversely, blocking stun altogether can disrupt legitimate communications applications.

The deeper issue is that the responsibility for updating is split between the chipset manufacturer, device vendor, service provider, and operator. The Realtek SDK is embedded in many products making it difficult for the organization to know which devices are actually affected. Devices that run out of support but still work also create an "invisible" infrastructure that the usual patching policy does not cover.

Hunting Signals and Mitigation Measures

  • Inventory of routers, DVRs, cameras and embedded devices with Internet exposure administration services; determination of firmware and support status.
  • Prioritize CVE-2021-35394 and vulnerabilities exploited in the campaign; isolate or replace unpatched equipment.
  • Reduce the attack surface by closing unnecessary services, limiting the source of administrative access, and segmenting IoT from user networks, servers.
  • Hunt for files /root/.cling, /usr/local/bin/.cling, abnormal changes in the startup script and the wget program are replaced.
  • Repeated Binding Request sequence analysis to multiple stun endpoints, all-zero transaction IDs, non-standard UDP subscriptions, and abnormal TTL variances.

Lessons from the ClingSTUN Profile

ClingSTUN doesn't need to invent a new protocol to avoid attention; it just needs to put malicious behavior in a traffic layer that the business is accustomed to trusting. Effective defenses must therefore combine network context with progress status, file integrity, and asset profile, rather than evaluating each indicator individually.

For the organization, the long-term priority is to maintain the correct device portfolio, force the firmware and support period to become procurement criteria, and have a roadmap to eliminate unpatchable hardware. For the security community, the campaign is a reminder that old vulnerabilities in the popular product can still create new botnets when the IoT ecosystem is not evenly maintained.

VNCyberS compiled from Nozomi Networks Labs, FortiGuard Labs, and The Hacker News

Contact Us

Email: [email protected]
Phone: +84 903260277