Cling Botnet Abusing STUN Infrastructure for C2
Score: 9/10

Cling Botnet Abusing STUN Infrastructure for C2

The Cling botnet exploits multiple IoT vulnerabilities to deploy a worm-like malware that repurposes legitimate STUN traffic and infrastructure for command-and-control communications.

Executive Summary

Security researchers have identified a new IoT botnet, dubbed Cling, which targets internet-exposed routers, DVRs, and cameras. The malware primarily gains initial access by exploiting CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle SDK, but also carries exploits for several other vulnerabilities across multiple vendors. Once a device is compromised, Cling establishes persistence and attempts to spread recursively in a worm-like fashion.

Cling is technically significant for its innovative use of Session Traversal Utilities for NAT (STUN) as a command-and-control (C2) channel. It sends malformed STUN binding requests to a list of public servers and waits for commands encoded within the STUN transaction ID field. By spoofing IP addresses associated with high-reputation services like Google's public STUN servers, the botnet masks its malicious activity as innocuous network traffic, making detection via standard network monitoring difficult.

The business impact is substantial for the OT and IoT sectors, as the botnet is designed for denial-of-service (DoS) attacks, proxy relaying, and TCP tunneling. The abuse of legitimate infrastructure and the vulnerability of unpatched legacy SDKs present a persistent threat to critical infrastructure and commercial facilities that rely on embedded networking hardware.

Key Details

Threat Name

Cling Botnet

Affects

Realtek Jungle SDK, Realtek SDK, Eir D1000 router, MVPower CCTV DVR, LB-LINK routers, FiberHome SR1041F router, China Mobile HG6543C4, TBK DVR, Linksys, IoT routers, Access points, Repeaters, FiberHome SR1041F

Adversary

Cling

Malware/Tools

Cling, Mirai, KATARU

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance8
Enterprise Relevance8
Clarity & Structure9
Technical Depth9