Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
The Cling malware exploits Realtek SDK vulnerabilities to build a botnet, disguising its command-and-control traffic as legitimate Google STUN service replies to evade detection.

A sophisticated malware strain dubbed "Cling" is actively compromising Internet of Things (IoT) devices, transforming them into a botnet while employing a cunning tactic to evade detection: it disguises its command-and-control (C2) traffic as legitimate replies from Google's public STUN (Session Traversal Utilities for NAT) service. This technique allows attackers to issue instructions to compromised devices, making them appear as routine network communications used by applications to establish connections across network boundaries.
The infection vector for Cling malware targets devices running vulnerable Realtek software, a common component in routers, access points, and other network appliances. Researchers from Nozomi Networks identified Cling while observing a surge in exploitation attempts against CVE-2021-35394, a known vulnerability within Realtek SDKs. The malware leverages these established entry points to gain initial access and establish a foothold.
Once infected, Cling uses seemingly innocuous STUN exchanges to register compromised devices and receive commands from its operators. STUN is a protocol that helps devices discover their public IP address and the network port assigned by their router, commonly used in video conferencing and browser-based communications. By mimicking this traffic, Cling can operate in the background without immediately raising alarms among security teams.
The malware's capabilities are extensive, including spreading to other vulnerable devices, relaying traffic, opening network tunnels, and launching denial-of-service (DoS) attacks. Researchers have observed Cling operators targeting critical infrastructure, including internet providers, university networks, and gaming services, though specific details on the scale of infections or confirmed outages remain undisclosed.
Cling's C2 mechanism is particularly noteworthy. It contacts hardcoded STUN servers and, after gathering port information, sends a separate registration message. While these messages are not valid STUN traffic, one server exhibited an unusual response that prompted further investigation. Commands are embedded within the 12-byte transaction identifier field of the STUN protocol, a field normally used to match requests with replies. This method of obfuscation is reminiscent of browser-based malware that hijacks familiar communication patterns.
Researchers believe the command packets appear to originate from Google's STUN infrastructure due to source-address spoofing, though they have not confirmed any compromise of Google's services. The presence of legitimate STUN endpoints in the traffic necessitates careful analysis alongside protocol anomalies and device behavior to identify malicious activity.
Beyond the STUN traffic manipulation, Cling also incorporates exploits for several other vulnerabilities, including CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, and CVE-2016-20016, broadening its attack surface across various router and video-recording equipment models. To ensure persistence, the malware creates hidden copies of itself and adds startup entries, and it also replaces a standard download utility to ensure future downloads trigger its execution.
Nozomi Networks recommends that organizations review exposed appliances, patch the identified vulnerabilities, and restrict inbound access where updates are unavailable. Network segmentation can also limit exposure. Defenders should scrutinize startup configurations for modifications and investigate unusual STUN requests with all-zero transaction identifiers, unexpected UDP registration messages, and deviations from normal device network behavior. Relying solely on the reputation of server addresses is insufficient when attackers can forge the apparent source of command traffic.