malware
Published 2026-10-01
Verified 2026-10-05

Cling / ClingSTUN IoT botnet hides C2 inside public STUN traffic — Nozomi (1 Oct) and FortiGuard (5 Oct) track two dozen router, camera and DVR exploits incl. Realtek CVE-2021-35394

Nozomi Networks Labs (1 October 2026) describes Cling, a botnet it found while investigating a spike in exploitation of CVE-2021-35394, the Realtek Jungle SDK 'UDPServer' diagnostic-daemon command injection (CVSS 3.1 9.8; on the CISA KEV catalog since December 2021). The attack sends UDP datagrams starting with orf; plus shell commands that use BusyBox wget to fetch and run the bot. The analysed MIPS sample also carries exploits for CVE-2014-8361 (Realtek SDK), CVE-2023-26801 (LB-LINK), CVE-2024-3721 (TBK DVR), CVE-2025-34037 (Linksys), CVE-2016-10372 (Eir D1000), CVE-2023-41011 (FiberHome / China Mobile router) and CVE-2016-20016 (MVPower DVR). It persists by copying itself to /root/.cling and /usr/local/bin/.cling, adding entries to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot, and replacing the wget binary so it re-runs whenever wget is called. Its command channel imitates STUN, the NAT-traversal protocol used by Teams, Zoom, Webex and WebRTC: every ~5 seconds it queries 13 hard-coded public STUN servers (including a Google address), sends a non-standard registration packet with its mapped ports and infection tag, then takes commands hidden in the 12-byte STUN transaction ID. Nozomi saw commands appear to come from Google STUN infrastructure and assesses spoofed source addresses as the likely explanation. Capabilities: spreading, proxying, tunnelling and DDoS; observed attack orders targeted an internet provider, university infrastructure and gaming services. No infection count or confirmed outages published; no Australian victims reported. Wire: Cybersecurity News 5 Oct. UPDATE (FortiGuard Labs, 5 Oct 2026): Fortinet tracks the same malware as ClingSTUN, a back-connect proxy backdoor, across three phases with different download servers. It was first delivered through CVE-2022-36553 (Hytec Inter HWL-2511-SS routers), then CVE-2025-34035 (EnGenius IoT cloud service) and CVE-2024-23625 (D-Link UPnP), then CVE-2021-35394 (Realtek), CVE-2023-1389 (TP-Link Archer AX21), CVE-2024-7029 (AVTECH AVM1203), CVE-2024-10915 (D-Link) and a goform buffer overflow across several vendors; SecurityWeek counts about two dozen exploited flaws including Ivanti, Lantronix, Linear, MeiG, Sunhillo and Tenda devices. Builds exist for ARM, x86, x86-64, MIPS and PowerPC. Newer versions kill the watchdog and competing malware, hide their process details behind copied PID 1 metadata, and send STUN binding requests to 24 (later 13) public endpoints. Fortinet rates it High severity.

Product
Internet-exposed routers, access points, repeaters, DVRs and other IoT devices built on the Realtek Jungle SDK and other vulnerable firmware
Versions
CVE-2021-35394: Realtek Jungle SDK v2.x up to v3.4.14B; plus devices affected by CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, CVE-2016-20016; FortiGuard adds CVE-2022-36553, CVE-2025-34035, CVE-2024-23625, CVE-2023-1389, CVE-2024-7029, CVE-2024-10915
CVSS
(CVE-2021-35394, CVSS 3.1 NVD)
Exploited in Australia?
unknown
Patch to
Apply vendor firmware with the Realtek SDK fix, or replace end-of-life routers, DVRs and access points that will never get one. Block internet access to device management and UDP diagnostic services. Hunt for UDP payloads starting with orf;, /root/.cling or /usr/local/bin/.cling, edits to inittab or rcS, a wget.r / wget.p pair, and STUN traffic from devices that never run voice or video apps, especially packets with an all-zero transaction ID.

Primary: Nozomi Networks Labs — A STUNning disguise: Cling malware masquerades as Google (1 Oct 2026) · Vendor: NVD — CVE-2021-35394 Realtek Jungle SDK UDPServer command injection (CVSS 9.8; CISA KEV) · CVE: CVE-2021-35394, CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, CVE-2016-20016, CVE-2022-36553, CVE-2025-34035, CVE-2024-23625, CVE-2023-1389, CVE-2024-7029, CVE-2024-10915 · FortiGuard Labs — ClingSTUN Linux backdoor abuses public STUN infrastructure (5 Oct 2026)

vulnerabilities network