Cling Botnet Hides Commands in the STUN Transaction ID and Spreads Through Realtek Flaw CVE-2021-35394
Security / explainer
Cling Botnet Hides Commands in the STUN Transaction ID and Spreads Through Realtek Flaw CVE-2021-35394
Nozomi Networks says the malware sends traffic that resembles ordinary Google STUN replies, so defenders have to hunt for all-zero transaction IDs instead of blocking an address.

The Cling botnet turns routers and DVRs into flood and proxy nodes, and takes its orders through STUN, the protocol that lets devices behind a home router discover their public address. Nozomi Networks Labs described it on Oct. 1, and The Hacker News reported on Oct. 5 that Fortinet's FortiGuard Labs had added a follow-up analysis.
The entry point is CVE-2021-35394, a command-injection flaw in the diagnostic component of the Realtek Jungle SDK, rated 9.8 out of 10 on the CVSS severity scale. It is five years old and patched, so this is exploitation of an old vulnerability, not a new one. The open question is how many deployed devices still run unpatched firmware, and neither source counts them.
How an exploit becomes a bot
Nozomi's post says the exploit sends UDP datagrams that begin with the string orf; followed by shell commands. Those commands use BusyBox wget to fetch a binary and run it with realtek.selfrep as its argument. The main sample Nozomi analysed is a MIPS binary. The Hacker News dates a rise in attempts to around Sept. 5; Nozomi's own post reports rising telemetry without giving that date.
The malware does not rely on one flaw. Its sample embeds exploit code for seven other bugs:
| CVE | Device named by The Hacker News |
|---|---|
| CVE-2014-8361 | Realtek SDK |
| CVE-2016-10372 | Eir D1000 |
| CVE-2016-20016 | MVPower CCTV DVR |
| CVE-2023-26801 | LB-LINK |
| CVE-2023-41011 | FiberHome SR1041F and China Mobile HG6543C4 |
| CVE-2024-3721 | TBK DVR |
| CVE-2025-34037 | Linksys |
Fortinet's account, as relayed by The Hacker News, lists a longer set of initial-access flaws across D-Link, Tenda, TP-Link, Ivanti and other vendors, and seven self-propagation exploits including CVE-2026-87827 in KGUARD DVRs. Fortinet calls the malware a backconnect proxy backdoor that turns infected devices into remotely controlled proxy nodes.

The router above is illustrative only. Neither source names Digicel equipment as affected.
How commands travel inside STUN
Nozomi describes four steps. The bot sends STUN Binding Requests to 13 hard-coded servers about every five seconds, using an all-zero transaction ID that the STUN specification does not allow. It records the mapped ports the servers return. It then sends each server a registration datagram that is not valid STUN, carrying those ports and an infection tag, and compliant servers ignore it. Finally it listens on the mapped ports for packets whose 12-byte transaction ID field holds an operator command.
One server, 145.249.115[.]184, answered with all-zero transaction IDs unlike the rest. Nozomi advertised different ports to each server and received commands on the port shared only with that one, which it says points to operator control or collusion. The commands appeared to come from 74.125.250[.]129, the address stun.l.google.com resolves to. Nozomi suspects the source address is spoofed, based on differing IP TTL values, which makes them look like ordinary STUN replies, so the Google address is not evidence of Google involvement.
The bot accepts eight commands: execute, scan and exploit, stop scanner, start TCP tunnel, stop TCP tunnel, proxy relay, stop proxy and flood.
What it leaves on the device
A UDP socket on port 33957 acts as a single-instance check. Copies land at /root/.cling and /usr/local/bin/.cling and are referenced from /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot, covering SysV and BusyBox init systems. As an alternative, Nozomi says the malware moves the real wget to wget.r, stores its path in wget.p and takes wget's place, so every call to wget reruns the malware before invoking the real binary.
Observed flood targets were 112.151.157[.]222 on port 8080, a South Korean ISP; 192.170.240[.]137 on port 53, a University of Chicago cluster; and Minecraft servers at 23.81.40[.]193 and 147.185.221[.]129 on port 25565.
What defenders can look for
Nozomi recommends inventorying internet-exposed routers and IoT devices, especially those with Realtek SDK or the listed CVEs, then patching or segmenting them. For detection it says to hunt for repeated STUN requests with all-zero transaction IDs and for non-STUN UDP sent to STUN endpoints, and to check hosts for .cling files, init-script entries and wget.r and wget.p files. Its indicators include two MIPS sample hashes and loader hosts 118.45.196[.]225, 120.193.219[.]210 and 58.211.144[.]243 on port 800.
The Hacker News article lists no hashes and does not give the full set of 13 STUN servers, so blocking by address alone would cover only part of the channel. Internet-facing appliances are being hit across the board this month, as in the FortiMail zero-day with no patch and the NetScaler SAML zero-day, but Cling is aimed at home and branch gear that rarely gets a bulletin.
Sources
More in Security
- 01Apple Fixes CoreGraphics Flaw CVE-2026-86950 in iOS 26.7.1 After Meta Reports Targeted AttacksApple's entry says a crafted file can run code and that exploitation may have hit specific people on iOS versions before iOS 27, but it names no victims and no attacker.
- 02NetScaler SAML Zero-Day CVE-2026-88779 Was Exploited Days After Two Others, and CISA's Deadline Is TodayCitrix rates the flaw 8.7 and calls it a denial of service, but a researcher's honeypot ran a downloaded binary, and appliances patched for last week's bugs need a second upgrade.
- 03Cloudflare's Open-Source Audit Skill Is at 25,900 Stars, but Its Own Post Shows 20,799 Candidates Became 7,245 Actionable FindingsThe repository trending on GitHub is the 450-line starting point. The funnel numbers in Cloudflare's June write-up describe a different system that has not been released.
- 04FortiMail CVE-2026-104286: Unauthenticated File Write Exploited at Disclosure, With No Fixed Build YetFortinet's advisory FG-IR-26-175 lists fixes for 7.4, 7.6 and 8.0 as pending; the interim steps are disabling IBE and closing the management interface.