Cling Botnet Turns Old Router and DVR Bugs Into STUN-Speaking Proxy Nodes — Nozomi and FortiGuard Track the Linux Backdoor
Cling Botnet Turns Old Router and DVR Bugs Into STUN-Speaking Proxy Nodes — Nozomi and FortiGuard Track the Linux Backdoor
Threat researchers are tracking a Linux botnet that repurposes ordinary STUN protocol traffic into a command-and-control channel while it chews through some of the oldest unpatched bugs in the internet-of-things catalog. Nozomi Networks said it observed a spike in attempts to exploit CVE-2021-35394 — the CVSS 9.8 remote code execution flaw in Realtek's Jungle SDK — starting around September 5, with a subset of the activity delivering a botnet it calls Cling. FortiGuard Labs, analyzing the same malware as ClingSTUN, describes a back-connect proxy backdoor now carrying exploits for roughly two dozen initial-access vulnerabilities.
Cling's trick is making C2 look like NAT traversal. The bot sends STUN Binding Requests to a hardcoded list of 13 public STUN servers roughly every five seconds — with the transaction ID set to all zeros instead of a random value — records the externally mapped ports reported back, then registers with a custom UDP datagram that includes the mapped ports and an infection tag such as realtek.selfrep or selfrep.router. Operator commands arrive encoded in the STUN transaction ID field of incoming packets. "From a network monitoring perspective, the activity appears as innocuous interaction with STUN servers," Nozomi said — traffic that blends with legitimate VoIP and WebRTC flows, which is the point.
The vulnerability list is a tour of the unpatched internet. FortiGuard observed initial access via command injection and RCE flaws in EnGenius, D-Link, TP-Link Archer, Ivanti, Tenda, Hytec, Linear, Sunhillo, Realtek and more — most of them years old — with download sources rotating across three periods. The Nozomi sample embeds self-propagation exploits for a museum wing of CVEs: Realtek CVE-2014-8361, Eir D1000 CVE-2016-10372, MVPower DVR CVE-2016-20016, LB-LINK CVE-2023-26801, FiberHome CVE-2023-41011 and Linksys CVE-2025-34037. Persistence is textbook Linux IoT: copies to /root/.cling and /usr/local/bin/.cling, hooks /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot, binds port 33957 as a single-instance check, and even replaces the wget binary so any legitimate use re-executes the malware. Payloads ship for x86-64, ARM, 80386, MIPS and PowerPC.
The capability list is short and commercial: propagation, proxying, tunneling and denial-of-service commands. FortiGuard's guidance cuts against reflexive blocklists — the public STUN servers being abused are legitimate services, so defenders should "assess STUN activity alongside suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic" rather than classifying STUN itself as malicious. It is the same edge-device hygiene lesson as the MikroTik SSH-chain takeovers we covered in September: the bug list is old, the devices are everywhere, and nobody is patching them.
What Should You Do?
- Patch or retire the usual-suspect internet-facing devices — the campaign's entire CVE list is public and mostly years old, from Realtek SDK gear to Ivanti, D-Link and TP-Link fleets.
- Inventory what is actually exposed: run an external scan and reconcile every internet-facing embedded device against its firmware support status.
- Watch for STUN traffic from devices with no VoIP or WebRTC reason to make it — especially recurring five-second UDP keepalives to multiple public STUN servers.
- Segment IoT and block unnecessary outbound UDP from device VLANs — egress filtering is the layer that catches a bot whose command channel looks like a video call.
The WAF Angle
There is no WAF in front of a DVR, and that is the point: this botnet is a reminder that the attack surface most organizations never model is the pile of small boxes answering on public IP addresses. Where edge devices do sit behind a reverse proxy or WAF, command-injection rules for the affected endpoints add real friction, but for everything else the detection layer is egress — and Cling's traffic is distinctive at flow level even when the payload is opaque, because a device sending five-second STUN probes to 13 servers is not making video calls. The all-zero transaction IDs and nonconforming registration datagrams are patterns any netflow tool can carry as signatures. If your monitoring treats STUN as "probably VoIP, ignore it," this campaign is the reason to stop.