Security researchers from Nozomi Networks and Fortinet have identified a new, sophisticated botnet malware named Cling (or ClingSTUN). The malware targets a variety of internet-facing IoT devices, including routers and DVRs, by exploiting a wide array of remote code execution (RCE) and command injection vulnerabilities. Its most notable feature is the use of the STUN (Session Traversal Utilities for NAT) protocol for command-and-control (C2) communications, allowing it to masquerade as legitimate traffic. Compromised devices are turned into backconnect proxy backdoors, enabling operators to launch DoS attacks, tunnel traffic, and propagate the botnet further.
The ClingSTUN botnet spreads by scanning the internet for vulnerable IoT devices and exploiting known flaws. Researchers have observed it leveraging numerous CVEs, including a recent spike in exploitation attempts against CVE-2021-35394, a critical RCE vulnerability in the Realtek Jungle SDK. The initial infection is typically carried out via a shell script downloader that fetches the appropriate malware binary for the device's architecture (e.g., ARM, MIPS, x86-64).
Once a device is compromised, the Cling malware establishes persistence and connects to its C2 infrastructure.
The most innovative aspect of ClingSTUN is its C2 mechanism. It uses the STUN protocol, which is normally used for NAT traversal in applications like VoIP and WebRTC. By embedding its C2 communications within STUN packets, the malware's traffic can be difficult to distinguish from legitimate network activity, thereby evading simple signature-based detection. This is a form of T1572 - Protocol Tunneling.
ClingSTUN employs several techniques to ensure it survives a device reboot, a common challenge for IoT malware:
/etc/inittab, a classic Linux persistence method. This corresponds to T1547.006 - Kernel Modules and Extensions (in spirit, as it's a startup script).wget binary with a copy of itself. When any system process or script calls wget to download a file, it executes the malware instead. This is a form of Hijack Execution Flow (T1574).The botnet has been linked to the exploitation of numerous vulnerabilities, including:
CVE-2021-35394 (Realtek Jungle SDK RCE)CVE-2014-8361 (Realtek SDK Miniigd SOAP RCE)CVE-2016-10372 (MVPower DVR RCE)Compromised devices become part of a powerful botnet that can be used for various malicious purposes:
For the owners of the infected devices, the impact includes degraded performance, increased bandwidth usage, and the risk of their IP address being blacklisted for malicious activity.
No specific Indicators of Compromise (IOCs) such as C2 IPs, domains, or file hashes were provided in the source articles.
Security teams can hunt for signs of ClingSTUN infection with the following hints:
/etc/inittab/usr/bin/wgetwget against known-good values to detect replacement.UDP/3478) directed to destinations other than known, legitimate services (e.g., VoIP providers, WebRTC gateways). Anomaly detection can flag devices exhibiting this behavior./etc/inittab and binaries in /bin or /usr/bin.Keeping IoT device firmware up-to-date is the most effective way to prevent exploitation of known vulnerabilities.
Mapped D3FEND Techniques:
Use an egress firewall to block all outbound traffic from IoT devices by default, only allowing connections to known-good, necessary services.
Mapped D3FEND Techniques:
Placing IoT devices on a separate network segment prevents them from accessing critical internal systems if compromised.
Mapped D3FEND Techniques:
Researchers observe a significant increase in exploitation attempts for CVE-2021-35394, some of which deliver the Cling malware.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.