New "ClingSTUN" Botnet Targets IoT Devices with Evasive C2

"ClingSTUN" Botnet Exploits IoT Devices Using STUN Protocol for C2

HIGH
October 6, 2026
5m read
MalwareIoT SecurityCyberattack

Related Entities

Products & Tech

Other

Cling ClingSTUN

Full Report

Executive Summary

Security researchers from Nozomi Networks and Fortinet have identified a new, sophisticated botnet malware named Cling (or ClingSTUN). The malware targets a variety of internet-facing IoT devices, including routers and DVRs, by exploiting a wide array of remote code execution (RCE) and command injection vulnerabilities. Its most notable feature is the use of the STUN (Session Traversal Utilities for NAT) protocol for command-and-control (C2) communications, allowing it to masquerade as legitimate traffic. Compromised devices are turned into backconnect proxy backdoors, enabling operators to launch DoS attacks, tunnel traffic, and propagate the botnet further.


Threat Overview

The ClingSTUN botnet spreads by scanning the internet for vulnerable IoT devices and exploiting known flaws. Researchers have observed it leveraging numerous CVEs, including a recent spike in exploitation attempts against CVE-2021-35394, a critical RCE vulnerability in the Realtek Jungle SDK. The initial infection is typically carried out via a shell script downloader that fetches the appropriate malware binary for the device's architecture (e.g., ARM, MIPS, x86-64).

Once a device is compromised, the Cling malware establishes persistence and connects to its C2 infrastructure.

Technical Analysis

C2 Communication

The most innovative aspect of ClingSTUN is its C2 mechanism. It uses the STUN protocol, which is normally used for NAT traversal in applications like VoIP and WebRTC. By embedding its C2 communications within STUN packets, the malware's traffic can be difficult to distinguish from legitimate network activity, thereby evading simple signature-based detection. This is a form of T1572 - Protocol Tunneling.

Persistence Mechanisms

ClingSTUN employs several techniques to ensure it survives a device reboot, a common challenge for IoT malware:

  1. System Startup Scripts: It appends itself to startup files like /etc/inittab, a classic Linux persistence method. This corresponds to T1547.006 - Kernel Modules and Extensions (in spirit, as it's a startup script).
  2. Binary Replacement: In a more novel approach, it replaces the legitimate wget binary with a copy of itself. When any system process or script calls wget to download a file, it executes the malware instead. This is a form of Hijack Execution Flow (T1574).

Exploited Vulnerabilities

The botnet has been linked to the exploitation of numerous vulnerabilities, including:

  • CVE-2021-35394 (Realtek Jungle SDK RCE)
  • CVE-2014-8361 (Realtek SDK Miniigd SOAP RCE)
  • CVE-2016-10372 (MVPower DVR RCE)
  • And many others affecting products from Eir, LB-LINK, FiberHome, China Mobile, TBK, and Linksys.

Impact Assessment

Compromised devices become part of a powerful botnet that can be used for various malicious purposes:

  • DDoS Attacks: The aggregated bandwidth of thousands of IoT devices can be used to launch powerful Distributed Denial-of-Service attacks.
  • Proxy Network: The botnet functions as a backconnect proxy, allowing threat actors to anonymize their own traffic and launch attacks that appear to originate from the compromised IoT devices around the world.
  • Further Propagation: The botnet is used to scan for and infect more vulnerable devices, increasing its size and power.

For the owners of the infected devices, the impact includes degraded performance, increased bandwidth usage, and the risk of their IP address being blacklisted for malicious activity.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) such as C2 IPs, domains, or file hashes were provided in the source articles.

Cyber Observables — Hunting Hints

Security teams can hunt for signs of ClingSTUN infection with the following hints:

Type
Network Traffic Pattern
Value
Outbound STUN traffic to unusual IPs
Description
IoT devices should typically only communicate with their manufacturer's cloud services. Outbound STUN traffic to unknown or non-standard servers is highly suspicious.
Type
File Path
Value
/etc/inittab
Description
Monitor for unauthorized modifications to this system startup configuration file.
Type
File Hash
Value
Hash of /usr/bin/wget
Description
Periodically check the hash of critical system binaries like wget against known-good values to detect replacement.
Type
Process Name
Value
Unusual processes consuming high CPU
Description
Look for unidentified processes running on IoT devices, especially those making outbound network connections.

Detection & Response

  • Network Behavior Analysis: Monitor outbound traffic from IoT devices. Since ClingSTUN uses STUN, look for STUN traffic (UDP/3478) directed to destinations other than known, legitimate services (e.g., VoIP providers, WebRTC gateways). Anomaly detection can flag devices exhibiting this behavior.
  • File Integrity Monitoring (FIM): On devices where it's possible, implement FIM to detect changes to critical system files like /etc/inittab and binaries in /bin or /usr/bin.
  • Device Isolation: If a device is suspected of being infected, immediately isolate it from the network to prevent it from participating in attacks or spreading the malware further.

Mitigation

  • Patch Management: The primary defense is to ensure all IoT devices are running the latest firmware from the manufacturer. This is especially critical for routers and DVRs, which are common targets.
  • Network Segmentation: Place IoT devices on a separate, isolated network segment with restricted internet access. Deny all outbound traffic by default and only allow connections to specific, required services.
  • Disable Unnecessary Services: Disable UPnP and other unnecessary services on routers and other IoT devices to reduce the attack surface.
  • Change Default Credentials: Always change the default administrator password on any new IoT device.

Timeline of Events

1
September 5, 2026
Researchers observe a significant increase in exploitation attempts for CVE-2021-35394, some of which deliver the Cling malware.
2
October 6, 2026
This article was published

MITRE ATT&CK Mitigations

Keeping IoT device firmware up-to-date is the most effective way to prevent exploitation of known vulnerabilities.

Mapped D3FEND Techniques:

Use an egress firewall to block all outbound traffic from IoT devices by default, only allowing connections to known-good, necessary services.

Mapped D3FEND Techniques:

Placing IoT devices on a separate network segment prevents them from accessing critical internal systems if compromised.

Mapped D3FEND Techniques:

Timeline of Events

1
September 5, 2026

Researchers observe a significant increase in exploitation attempts for CVE-2021-35394, some of which deliver the Cling malware.

Sources & References

New 'Cling' Botnet Malware Spreading via Unpatched Routers and DVRs
The Hacker News (thehackernews.com) •October 5, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

botnetmalwareIoTSTUNC2

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.