Cling botnet with STUN-based C2 and persistence
Malware Activity
Summary
Hide ▲
Show ▼
The Cling malware activity now includes STUN-based back-connect proxying that uses public STUN servers to keep infected systems reachable as remotely controlled proxy nodes. FortiGuard Labs said the campaign, published October 5, progressed through multiple waves of exploitation against internet-facing IoT devices, including CVE-2022-36553, CVE-2025-34035, and CVE-2024-23625, before expanding to a list of 24 vulnerabilities in the third period. The malware also copies itself, modifies boot scripts for persistence, hides behind process information from init, and supports remote command execution. FortiGuard further noted that the STUN traffic can resemble normal VoIP and WebRTC activity, making the proxy nodes harder to spot.
Related Happenings
ClingSTUN Linux proxy backdoor abusing IoT devices
Malware Activity
H score31
First: 05.10.2026 17:30
Last: 05.10.2026 17:30
Sources 1
How related:
A Linux proxy backdoor has been observed exploiting known, unpatched flaws in internet-facing IoT devices and abusing legitimate public STUN servers to keep compromised systems reachable as remotely controlled proxy nodes.
About this happening:
The ClingSTUN Linux proxy backdoor is turning unpatched internet-facing IoT devices into remotely controlled proxy nodes, expanding covert infrastructure for abuse. Th...
ClingSTUN Linux proxy backdoor abusing IoT devices
Malware ActivityHow related: A Linux proxy backdoor has been observed exploiting known, unpatched flaws in internet-facing IoT devices and abusing legitimate public STUN servers to keep compromised systems reachable as remotely controlled proxy nodes.
About this happening: The ClingSTUN Linux proxy backdoor is turning unpatched internet-facing IoT devices into remotely controlled proxy nodes, expanding covert infrastructure for abuse. Th...
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
Vulnerability
H score1
First: 20.04.2026 16:01
Last: 20.04.2026 16:01
Sources 1
About this happening:
The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
VulnerabilityAbout this happening: The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
Timeline
-
05.10.2026 14:46 1 articles · 3h ago
Threat actors exploit CVE-2021-35394 to deliver Cling
Exploitation ObservedThreat actors were observed attempting to exploit CVE-2021-35394 in the Realtek Jungle SDK, with a subset of the activity delivering the Cling botnet to vulnerable devices starting around September 5, 2026.
Show sources
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 — thehackernews.com — 05.10.2026 14:46
-
05.10.2026 14:46 3 articles · 3h ago
Cling botnet uses STUN traffic for hidden command-and-control
Technical Analysis UpdateCling uses a four-step STUN command-and-control routine that sends Binding Requests to 13 hard-coded servers, records the mapped ports returned by those servers, sends custom registration datagrams that include infection tags, and polls for operator commands encoded in the STUN transaction ID field. The malware also copies itself to /root/.cling and /usr/local/bin/.cling, appends those paths to startup files, and can replace wget so that legitimate command execution launches the malware.
Show sources
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 — thehackernews.com — 05.10.2026 14:46
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 — thehackernews.com — 05.10.2026 14:46
- ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes — www.infosecurity-magazine.com — 05.10.2026 17:30