Threat reportMalwareTL-2026-2857
Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394
Cling IoT botnet masquerades as Google STUN traffic for C2 (TL-2026-2857), also tracked as Cling, is a high-severity malware campaign scored CVSS 9.8, first published 2026-10-03. It has no confirmed attribution, affects Realtek Jungle SDK (MP Daemon / UDPServer), references 8 CVEs (CVE-2021-35394, CVE-2014-8361, CVE-2023-26801), maps to 10 MITRE ATT&CK techniques (T1001, T1037.004, T1046), and is covered by 9 detection rules and 19 indicators of compromise.
- CVSS
- 9.8/10High
- CVEs
- 8Referenced vulnerabilities
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-2857
- Threat ID
- TL-2026-2857
- Also known as
- Cling
- Severity
- HIGH
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- telecoms, consumer-iot, surveillance, critical-infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Cling IoT botnet masquerades as Google STUN traffic for C2
Malware and tooling: Cling
How Cling IoT botnet masquerades as Google STUN traffic for C2 works
Nozomi Networks Labs describes Cling, a MIPS embedded-Linux botnet that spreads through CVE-2021-35394 (Realtek Jungle SDK UDPServer/MP Daemon command injection) and hides its command channel in STUN Binding traffic, carrying operator commands in the 12-byte transaction ID and spoofing the source address of stun.l.google.com. It persists through init scripts and by replacing wget, and supports scanning, proxying, TCP tunneling and DDoS.
Cling was found by Nozomi Networks Labs while investigating exploitation of CVE-2021-35394, a Realtek Jungle SDK flaw (versions 2.0 through 3.4.14B) in the diagnostic 'MP Daemon', usually compiled as the 'UDPServer' binary listening on UDP 9034. Attackers send UDP datagrams beginning with 'orf;' followed by shell commands. The commands use BusyBox wget to fetch a MIPS (mipsel) binary from a loader host and execute it with an infection-method tag (for example 'realtek.selfrep') as the first argument.
On the device, the malware binds a socket with SO_REUSEADDR to TCP/UDP port 33957 as a single-instance check and exits if the bind fails. It copies itself to /root/.cling and /usr/local/bin/.cling and appends references to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot, which covers SysV and BusyBox init layouts. It also hijacks wget: the legitimate binary is moved to wget.r, its original path is stored in wget.p, and the malware takes its place, so later wget invocations re-run or reinstall the bot.
The C2 channel abuses STUN (RFC 8489). Every ~5 seconds the bot sends STUN Binding Requests to 13 hardcoded public STUN servers using an all-zero transaction ID instead of a random one. It then sends a non-standard registration datagram containing the infection tag and its mapped external ports to each server; compliant servers ignore it. The bot then listens on the mapped ports for UDP packets whose 12-byte STUN transaction ID field encodes operator commands. Nozomi identified 145.249.115.184:3478 as an operator-controlled STUN server because it answered with all-zero transaction IDs instead of echoing requests. Command packets were seen arriving from 74.125.250.129 (stun.l.google.com); Nozomi assesses this as UDP source-address spoofing, based on TTL differences.
Eight commands are encoded in the transaction ID: execute (download a payload from IP:port and pass it to system(3)), scan-and-exploit across IPv4, stop scanner, start TCP tunnel, stop TCP tunnel, proxy relay (bidirectional forwarding to a relay server), stop proxy, and flood (DDoS for a set duration). Observed DDoS targets included a South Korean ISP host (112.151.157.222:8080), a University of Chicago host (192.170.240.137:53) and two Minecraft servers (23.81.40.193:25565, 147.185.221.129:25565). Besides CVE-2021-35394, the bot embeds exploits for CVE-2014-8361 (Realtek SDK), CVE-2023-26801 (LB-LINK routers), CVE-2024-3721 (TBK DVR), CVE-2025-34037 (Linksys), CVE-2016-10372 (Eir D1000), CVE-2023-41011 (FiberHome SR1041F) and CVE-2016-20016 (MVPower CCTV DVR). No threat actor attribution is stated in the sources.
CVE-2021-35394 (CVSS 3.1 base 9.8, CWE-78) was published 2021-08-16 and is in the CISA KEV catalog. Unit 42 reported 134 million exploit attempts between August and December 2022 and counted about 190 affected device models from 66 vendors, with Mirai, Gafgyt, Mozi and RedGoBot using it. Defenders should hunt for .cling files, wget.r/wget.p artifacts, modified init scripts, repeated STUN Binding Requests with all-zero transaction IDs, and non-STUN UDP payloads sent to STUN endpoints. Source reputation alone is insufficient because the C2 spoofs a Google address.
MITRE ATT&CK techniques used in TL-2026-2857
Command and Control
T1001 Data Obfuscation; T1090 Proxy; T1095 Non-Application Layer Protocol; T1572 Protocol Tunneling
Persistence
Discovery
T1046 Network Service Discovery
Execution
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1498.001 Direct Network Flood
stealth
Affected products and versions in Cling IoT botnet masquerades as Google STUN traffic for C2
- Realtek — Jungle SDK (MP Daemon / UDPServer)
Vulnerable versions: 2.0 through 3.4.14B
Fixed in: Apply vendor patch per Realtek advisory - LB-LINK — Routers (CVE-2023-26801)
- TBK — DVR (CVE-2024-3721)
- Linksys — Routers (CVE-2025-34037)
- Eir — D1000 router (CVE-2016-10372)
- FiberHome — SR1041F (CVE-2023-41011)
- MVPower — CCTV DVR (CVE-2016-20016)
Remediation for Cling IoT botnet masquerades as Google STUN traffic for C2
Patches
- Apply vendor updates for Realtek Jungle SDK CVE-2021-35394 (fixed after v3.4.14B)
- Patch the embedded-exploit targets: CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, CVE-2016-20016
Immediate actions
- Hunt embedded devices for /root/.cling, /usr/local/bin/.cling, and wget.r / wget.p files beside wget in /bin, /sbin, /usr/bin, /usr/sbin and /usr/local/bin
- Alert on STUN Binding Requests with an all-zero transaction ID and on non-STUN UDP datagrams sent to STUN endpoints
- Block egress to 145.249.115.184 and the loader hosts 118.45.196.225, 120.193.219.210, 58.211.144.243 and 121.32.243.81
- Block inbound UDP 9034 from the internet to Realtek-based devices
Workarounds
- Replace or retire end-of-life devices that cannot be patched
- Audit /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot for unexpected entries and reflash compromised devices from known-good firmware
Longer-term hardening
- Remove unnecessary internet-facing access to routers, DVRs, access points and embedded appliances
- Segment vulnerable IoT and edge devices into isolated zones and treat them as network entry points
- Baseline asset connectivity and alert on deviations; inspect protocol behavior instead of relying on destination reputation alone
CVEs associated with Cling IoT botnet masquerades as Google STUN traffic for C2
CVE-2021-35394, CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, CVE-2016-20016
Weaknesses (CWE) in Cling IoT botnet masquerades as Google STUN traffic for C2
Timeline of Cling IoT botnet masquerades as Google STUN traffic for C2
- CVE-2021-35394 (Realtek Jungle SDK MP Daemon/UDPServer command injection and memory corruption, CVSS 9.8) is published in NVD.
- CVE-2021-35394 is listed in CISA's Known Exploited Vulnerabilities catalog (date per NVD KEV data).
- Start of the August-December 2022 window in which Unit 42 observed 134 million exploit attempts against CVE-2021-35394, across roughly 190 device models from 66 vendors.
- Mass exploitation of CVE-2021-35394 begins; RedGoBot first observed. Unit 42 later counts 134 million attempts from August to December 2022, with Mirai, Gafgyt and Mozi also using the flaw.
- End of the Unit 42 observation window for mass CVE-2021-35394 exploitation (134 million attempts August-December 2022), establishing the vulnerable Realtek population that Cling later targets.
- Nozomi Networks Labs publishes its analysis of Cling: STUN transaction-ID C2, spoofed stun.l.google.com source, wget hijack and eight embedded exploits.
- CyberPress also covers Cling, confirming 13 hardcoded STUN servers queried about every 5 seconds, all-zero transaction IDs and the suspected colluding server 145.249.115.184:3478.
- GBHackers reports on Cling, including the IOC set and MITRE ATT&CK mapping from the Nozomi research.
Sources cited for Cling IoT botnet masquerades as Google STUN traffic for C2
- Cling Malware Masquerades as Google STUN Traffic (GBHackers)
- A Stunning Disguise: Cling Malware Masquerades as Google STUN Traffic (Nozomi Networks Labs)
- NVD - CVE-2021-35394
- CISA Known Exploited Vulnerabilities Catalog
- Unit 42: Realtek SDK Vulnerability exploited at scale
- BleepingComputer: Botnets exploited Realtek SDK critical bug in millions of attacks
- SentinelOne Vulnerability Database: CVE-2021-35394
- Cling IoT Malware Masquerades as Google STUN Traffic to Hide C2 Communications (CyberPress)
- FortiGuard Outbreak Alert: Realtek SDK Attack
Detection coverage for TL-2026-2857
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2857 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.