A newly detailed malware strain dubbed “Cling” is targeting internet-connected devices by mimicking Google’s STUN service traffic to stealthily command compromised hardware. It begins life through vulnerabilities in Realtek-powered devices—old but unpatched flaws that leave routers, access points, repeaters and similar gear wide open.
What Cling Does and How It Hides in Plain Sight
Discovered by researchers at Nozomi Networks amid a surge of attacks exploiting CVE-2021-35394, Cling registers devices by sending frequent, hard-coded STUN requests every five seconds. The malware collects the public IP and port information returned by public STUN servers, then packages this data—along with tags that indicate how the infection started—into what appears to be legitimate but malformed STUN registration messages. Under the hood, this channel is used to hide commands from its operator.
The commands are so well camouflaged that they exploit fields normally used to match STUN requests and responses (12-byte transaction identifiers), and include behaviors like spoofed source addresses. While traffic appears to be coming from Google’s infrastructure, there’s no sign the STUN servers themselves have been compromised—rather, Cling forges parts of the connection to mask its malicious control flow.
Capabilities, Persistence & Why It Matters
Cling is far from benign. Its feature set includes executing shell commands, deploying additional payloads, enabling proxy relays and even staging denial-of-service and proxy-type operations. The sample analyzed by Nozomi includes exploits for a spectrum of vulnerabilities stretching back to 2014 up through mid-2025, allowing it to infect a wide variety of networked edge devices.
To maintain survival through power cycles, Cling installs hidden copies of its binary and alters startup scripts. It also replaces the system’s default download utility with a malicious version while keeping one legitimate copy tucked away, which allows it to re-trigger itself via routine tasks.
Detection and Defense: What to Do
Organizations with exposed Realtek-based appliances should immediately patch any known vulnerabilities. Where patches aren’t available, restricting remote access is essential. Network segmentation helps so compromised devices can’t reach critical systems. Checking for anomalies—like frequent STUN requests with zeroed transaction IDs, unusual UDP registration messages or replaced system utilities—can reveal Cling infections. Inspecting startup files for unauthorized changes is vital.
Some of the Indicators of Compromise (IoCs) include specific file paths (e.g. hidden .cling binaries under /usr/local/bin or ), altered startup entries in scripts like or , and preserved renamed versions of wget utilities. Also, SHA-1 and SHA-256 hashes of analyzed binaries and suspect loader URLs have been published to aid detection.
Cling was observed targeting high-capacity infrastructure including ISPs, academic networks and gaming services. No confirmed outage numbers are available yet, but its ability to engage in scanning, relay traffic and performance-degrading floods makes its potential serious.
What this means is a warning: even legacy or overlooked IoT devices can still fuel large scale cyberattacks. Malware like Cling shows that attackers are refining stealth techniques—by imitating benign traffic like STUN, they can evade many detection systems. It’s crucial to review all devices on your network, apply firmware updates, limit unnecessary remote exposure, and use behavioral as well as signature-based detection—not just trusted server lists—to avoid being quietly coopted into botnet infrastructure.