Executive Summary
Security researchers have identified a new IoT botnet, dubbed Cling, which targets internet-exposed routers, DVRs, and cameras. The malware primarily gains initial access by exploiting CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle SDK, but also carries exploits for several other vulnerabilities across multiple vendors. Once a device is compromised, Cling establishes persistence and attempts to spread recursively in a worm-like fashion.
Cling is technically significant for its innovative use of Session Traversal Utilities for NAT (STUN) as a command-and-control (C2) channel. It sends malformed STUN binding requests to a list of public servers and waits for commands encoded within the STUN transaction ID field. By spoofing IP addresses associated with high-reputation services like Google's public STUN servers, the botnet masks its malicious activity as innocuous network traffic, making detection via standard network monitoring difficult.
The business impact is substantial for the OT and IoT sectors, as the botnet is designed for denial-of-service (DoS) attacks, proxy relaying, and TCP tunneling. The abuse of legitimate infrastructure and the vulnerability of unpatched legacy SDKs present a persistent threat to critical infrastructure and commercial facilities that rely on embedded networking hardware.
Key Details
Threat Name
Cling Botnet
Affects
Realtek Jungle SDK, Realtek SDK, Eir D1000 router, MVPower CCTV DVR, LB-LINK routers, FiberHome SR1041F router, China Mobile HG6543C4, TBK DVR, Linksys, IoT routers, Access points, Repeaters, FiberHome SR1041F
Adversary
Cling
Malware/Tools
Cling, Mirai, KATARU
