FortiGuard Labs published research on Oct. 5 describing ClingSTUN, a Linux backdoor that uses legitimate public STUN servers for command and control and exploits about two dozen vulnerabilities in routers, DVRs and other IoT devices. Nozomi Networks separately reported the same botnet, which it calls Cling, in late September.
Nozomi Spots a Spike in CVE-2021-35394 Exploitation From Early September
Nozomi Networks, an operational technology security firm, saw a spike in exploitation attempts against CVE-2021-35394 starting around September 5. The flaw is a remote code execution bug in the Realtek Jungle SDK with a CVSS score of 9.8. A subset of those attempts delivered the botnet Nozomi named Cling.
FortiGuard Labs independently dubbed it ClingSTUN and described it as a Linux back-connect proxy backdoor. It targets about two dozen vulnerabilities in devices from Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda and TP-Link. It also carries self-propagation exploits for flaws in products from China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek and TBK.
Payloads Built for Five Processor Architectures
The malware ships payloads for x86-64, ARM, x86, MIPS and PowerPC, which lets it run across the mix of chips found in consumer routers, cameras and industrial gear. Researchers saw three variants. Nozomi dates the exploitation spike to around September 5, a month before FortiGuard’s October 5 report. The malware also kills competing processes on infected devices, a common step for botnets that want exclusive use of a host.
Why STUN Traffic Makes the Cling Botnet’s C2 Hard to Spot
The distinctive feature is the command channel. Infected hosts send registration messages and keepalives that are disguised as NAT-traversal traffic, the kind produced by legitimate STUN exchanges, and they connect to legitimate public STUN servers. FortiGuard advises defenders not to classify those STUN servers as attacker-controlled, since blocking them on that basis would misidentify ordinary infrastructure.
Instead, the firm recommends correlating STUN activity with suspicious processes, unexpected UDP connections and recurring keepalives on the same host. Hosts can also be checked for the hidden .cling files, the edited init scripts and activity on port 33957.
Persistence Through Init Scripts and a Replaced wget Binary
Cling copies itself into hidden files at /root/.cling and /usr/local/bin/.cling. It appends entries to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot so that it restarts after a reboot. An alternate persistence method replaces the wget binary. The malware also checks for a running copy of itself using port 33957, ensuring only one instance runs.
The exploit list spans routers, DVRs and IoT devices from vendors including Ivanti and Lantronix, so the operators are not aiming at a single device type.
The two research efforts reached the same malware from different directions. Nozomi traced it from a surge in exploitation attempts against one Realtek flaw, while FortiGuard analyzed the sample itself and cataloged its exploit list and persistence methods. Their different names for the botnet, Cling and ClingSTUN, refer to the same activity, and both vendors published within about a week of each other.
Proxy, Tunneling and DoS Capabilities Make Compromised Devices Multi-Purpose
Cling supports commands for propagation, proxying, tunneling and denial-of-service attacks. A back-connect proxy lets operators route traffic through compromised devices, hiding the origin of that traffic, while the DoS commands let them attack targets.
The reports describe a growing botnet but note no takedown. Neither Nozomi nor FortiGuard has named an operator or counted infected devices in the coverage available.
The target list includes a flaw from 2021 alongside others, which shows that old embedded-device bugs remain in use. Realtek appears both in the initial-access flaw and in the self-propagation list. A botnet that blends its command traffic into routine-looking STUN exchanges is harder for network defenders to spot.
