Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cling botnet with STUN-based C2 and persistence

Malware Activity
First reported
Last updated
Happening score
H score 34
2 unique sources, 2 articles

Summary

Hide ▲

The Cling malware activity now includes STUN-based back-connect proxying that uses public STUN servers to keep infected systems reachable as remotely controlled proxy nodes. FortiGuard Labs said the campaign, published October 5, progressed through multiple waves of exploitation against internet-facing IoT devices, including CVE-2022-36553, CVE-2025-34035, and CVE-2024-23625, before expanding to a list of 24 vulnerabilities in the third period. The malware also copies itself, modifies boot scripts for persistence, hides behind process information from init, and supports remote command execution. FortiGuard further noted that the STUN traffic can resemble normal VoIP and WebRTC activity, making the proxy nodes harder to spot.

Related Happenings

ClingSTUN Linux proxy backdoor abusing IoT devices

Malware Activity
H score31 First: 05.10.2026 17:30 Last: 05.10.2026 17:30 Sources 1

How related: A Linux proxy backdoor has been observed exploiting known, unpatched flaws in internet-facing IoT devices and abusing legitimate public STUN servers to keep compromised systems reachable as remotely controlled proxy nodes.

About this happening: The ClingSTUN Linux proxy backdoor is turning unpatched internet-facing IoT devices into remotely controlled proxy nodes, expanding covert infrastructure for abuse. Th...

TBK DVR command injection flaw actively exploited (CVE-2024-3721)

Vulnerability
H score1 First: 20.04.2026 16:01 Last: 20.04.2026 16:01 Sources 1

About this happening: The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...

Timeline

  1. 05.10.2026 14:46 1 articles · 3h ago

    Threat actors exploit CVE-2021-35394 to deliver Cling

    Exploitation Observed

    Threat actors were observed attempting to exploit CVE-2021-35394 in the Realtek Jungle SDK, with a subset of the activity delivering the Cling botnet to vulnerable devices starting around September 5, 2026.

    Show sources
  2. 05.10.2026 14:46 3 articles · 3h ago

    Cling botnet uses STUN traffic for hidden command-and-control

    Technical Analysis Update

    Cling uses a four-step STUN command-and-control routine that sends Binding Requests to 13 hard-coded servers, records the mapped ports returned by those servers, sends custom registration datagrams that include infection tags, and polls for operator commands encoded in the STUN transaction ID field. The malware also copies itself to /root/.cling and /usr/local/bin/.cling, appends those paths to startup files, and can replace wget so that legitimate command execution launches the malware.

    Show sources