MalwareCritical

Cling botnet hides commands in STUN traffic while exploiting dozens of router flaws

FortiGuard Labs and Nozomi Networks describe a Linux botnet that disguises its command channel as replies from a Google STUN server and spreads through router and DVR flaws.

Cling botnet hides commands in STUN traffic while exploiting dozens of router flaws

At a glance

  • The Hacker News reports that exploit attempts against Realtek Jungle SDK flaw CVE-2021-35394 spiked around 5 September 2026 and some of them delivered the Cling botnet.
  • Cling polls 13 hardcoded STUN servers every five seconds and reads operator commands out of STUN transaction IDs, according to The Hacker News.
  • SecurityWeek reports FortiGuard Labs documented exploits for roughly two dozen flaws across vendors including D-Link, Tenda, TP-Link, Ivanti, Lantronix and Avtech.
  • The malware turns infected routers and DVRs into proxies and can also run TCP tunnels, scan for new victims and launch denial-of-service floods.

A Linux botnet that disguises its command-and-control traffic as ordinary NAT-traversal chatter is spreading through routers and digital video recorders, researchers at Nozomi Networks and Fortinet's FortiGuard Labs say. The Hacker News reports that the malware, called Cling or ClingSTUN, turns ordinary STUN behaviour into a working command channel, and that exploit attempts against the Realtek Jungle SDK vulnerability it leans on most heavily spiked around 5 September 2026. Nozomi Networks published the first report in late September, and FortiGuard Labs followed with further analysis on 5 October 2026, according to The Hacker News.

What happened

The primary way in is CVE-2021-35394, a critical remote code execution flaw in the Realtek Jungle SDK carrying a CVSS score of 9.8, The Hacker News reports. That software development kit has been embedded in consumer and small-business networking gear from many vendors for years, which is why a five-year-old bug is still a productive target. The Hacker News says only a subset of the exploitation attempts in that September spike actually delivered Cling payloads.

The operators did not stop at one bug. According to The Hacker News, Cling ships with hardcoded exploit logic for seven further vulnerabilities used for self-propagation, affecting Realtek SDK (CVE-2014-8361), MVPower CCTV DVRs (CVE-2016-20016), LB-LINK routers (CVE-2023-26801), FiberHome and China Mobile devices (CVE-2023-41011), TBK DVRs (CVE-2024-3721), Linksys gear (CVE-2025-34037) and KGUARD DVRs (CVE-2026-87827). SecurityWeek reports that FortiGuard Labs documented exploit attempts against roughly two dozen flaws in total, across vendors including Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda and TP-Link.

Technical details

The command channel is what makes Cling unusual. The Hacker News describes a four-step loop: the malware sends STUN binding requests to 13 hardcoded servers roughly every five seconds, records the external port each response reports back, sends a custom registration message to all of those servers tagged with the infection vector it used, then polls for operator commands encoded inside STUN transaction IDs. The operators go a step further and shape the replies so they appear to come from one of the most widely used STUN services on the internet, stun.l.google.com at 74.125.250.129.

One genuine command server stands out for a sloppy detail, per The Hacker News: 145.249.115.184 returns transaction IDs that are all zeroes, which no legitimate STUN server does. The malware copies itself to /root/.cling and /usr/local/bin/.cling, and binds port 33957 to make sure only one copy runs. For persistence it appends entries to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot on SysV and BusyBox systems, and replaces the legitimate wget binary while keeping the original, so the malware runs whenever something calls wget. Builds exist for ARM, Intel 80386, MIPS R3000, PowerPC and x86-64.

Who is affected and what to do

SecurityWeek describes Cling as a back-connect proxy that turns infected systems into proxies for its operators; The Hacker News adds that the command set also covers recursive scanning and worm-like propagation, setting up and tearing down TCP tunnels, and denial-of-service attacks. It lists flooding targets already observed, including a South Korean ISP address on port 8080, a University of Chicago cluster on port 53 and two Minecraft servers on port 25565.

Patching is the practical answer: apply firmware updates that fix CVE-2021-35394 and the other embedded vulnerabilities, and retire devices whose vendors no longer ship updates. SecurityWeek says defenders should watch for suspicious process behaviour, unexpected UDP connections and recurring keepalive traffic. On a device you can inspect, the hidden .cling files, a listener on port 33957 and a modified wget are direct signs of infection.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.