# Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394

> Nozomi Networks Labs describes Cling, a MIPS embedded-Linux botnet that spreads through CVE-2021-35394 (Realtek Jungle SDK UDPServer/MP Daemon command injection) and hides its command channel in STUN Binding traffic, carrying operator commands in the 12-byte transaction ID and spoofing the source address of stun.l.google.com. It persists through init scripts and by replacing wget, and supports scanning, proxying, TCP tunneling and DDoS.

- **Published:** 2026-10-03T00:00:00Z
- **Last reviewed:** 2026-10-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2857
- **ID:** TL-2026-2857
- **Severity:** HIGH (CVSS 9.8)
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2021-35394, CVE-2014-8361, CVE-2023-26801, CVE-2024-3721, CVE-2025-34037, CVE-2016-10372, CVE-2023-41011, CVE-2016-20016

## Description

Cling was found by Nozomi Networks Labs while investigating exploitation of CVE-2021-35394, a Realtek Jungle SDK flaw (versions 2.0 through 3.4.14B) in the diagnostic 'MP Daemon', usually compiled as the 'UDPServer' binary listening on UDP 9034. Attackers send UDP datagrams beginning with 'orf;' followed by shell commands. The commands use BusyBox wget to fetch a MIPS (mipsel) binary from a loader host and execute it with an infection-method tag (for example 'realtek.selfrep') as the first argument.

On the device, the malware binds a socket with SO_REUSEADDR to TCP/UDP port 33957 as a single-instance check and exits if the bind fails. It copies itself to /root/.cling and /usr/local/bin/.cling and appends references to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot, which covers SysV and BusyBox init layouts. It also hijacks wget: the legitimate binary is moved to wget.r, its original path is stored in wget.p, and the malware takes its place, so later wget invocations re-run or reinstall the bot.

The C2 channel abuses STUN (RFC 8489). Every ~5 seconds the bot sends STUN Binding Requests to 13 hardcoded public STUN servers using an all-zero transaction ID instead of a random one. It then sends a non-standard registration datagram containing the infection tag and its mapped external ports to each server; compliant servers ignore it. The bot then listens on the mapped ports for UDP packets whose 12-byte STUN transaction ID field encodes operator commands. Nozomi identified 145.249.115.184:3478 as an operator-controlled STUN server because it answered with all-zero transaction IDs instead of echoing requests. Command packets were seen arriving from 74.125.250.129 (stun.l.google.com); Nozomi assesses this as UDP source-address spoofing, based on TTL differences.

Eight commands are encoded in the transaction ID: execute (download a payload from IP:port and pass it to system(3)), scan-and-exploit across IPv4, stop scanner, start TCP tunnel, stop TCP tunnel, proxy relay (bidirectional forwarding to a relay server), stop proxy, and flood (DDoS for a set duration). Observed DDoS targets included a South Korean ISP host (112.151.157.222:8080), a University of Chicago host (192.170.240.137:53) and two Minecraft servers (23.81.40.193:25565, 147.185.221.129:25565). Besides CVE-2021-35394, the bot embeds exploits for CVE-2014-8361 (Realtek SDK), CVE-2023-26801 (LB-LINK routers), CVE-2024-3721 (TBK DVR), CVE-2025-34037 (Linksys), CVE-2016-10372 (Eir D1000), CVE-2023-41011 (FiberHome SR1041F) and CVE-2016-20016 (MVPower CCTV DVR). No threat actor attribution is stated in the sources.

CVE-2021-35394 (CVSS 3.1 base 9.8, CWE-78) was published 2021-08-16 and is in the CISA KEV catalog. Unit 42 reported 134 million exploit attempts between August and December 2022 and counted about 190 affected device models from 66 vendors, with Mirai, Gafgyt, Mozi and RedGoBot using it. Defenders should hunt for .cling files, wget.r/wget.p artifacts, modified init scripts, repeated STUN Binding Requests with all-zero transaction IDs, and non-STUN UDP payloads sent to STUN endpoints. Source reputation alone is insufficient because the C2 spoofs a Google address.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059.004 Unix Shell
- T1037.004 RC Scripts
- T1574 Hijack Execution Flow
- T1095 Non-Application Layer Protocol
- T1001 Data Obfuscation
- T1572 Protocol Tunneling
- T1090 Proxy
- T1046 Network Service Discovery
- T1498.001 Direct Network Flood

## Sources

- [Cling Malware Masquerades as Google STUN Traffic (GBHackers)](https://gbhackers.com/cling-malware-masquerades-as-google-stun-traffic/)
- [A Stunning Disguise: Cling Malware Masquerades as Google STUN Traffic (Nozomi Networks Labs)](https://www.nozominetworks.com/blog/a-stunning-disguise-cling-malware-masquerades-as-google-)
- [NVD - CVE-2021-35394](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2021-35394)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)
- [Unit 42: Realtek SDK Vulnerability exploited at scale](https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/)
- [BleepingComputer: Botnets exploited Realtek SDK critical bug in millions of attacks](https://www.bleepingcomputer.com/news/security/botnets-exploited-realtek-sdk-critical-bug-in-millions-of-attacks/)
- [SentinelOne Vulnerability Database: CVE-2021-35394](https://www.sentinelone.com/vulnerability-database/cve-2021-35394/)
- [Cling IoT Malware Masquerades as Google STUN Traffic to Hide C2 Communications (CyberPress)](https://cyberpress.org/cling-iot-malware-masquerades-as-google-stun/)
- [FortiGuard Outbreak Alert: Realtek SDK Attack](https://www.fortiguard.com/cn/outbreak-alert/html/realtek-sdk-attack)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2857
