Particle.news

ClingSTUN Malware Turns Unpatched IoT Devices Into STUN-Based Proxy Botnet

Researchers say the malware hides commands inside legitimate STUN traffic so infected devices can register and receive instructions through public NAT-traversal servers.

Overview

  • Security firms published detailed analyses on October 5 that show ClingSTUN uses STUN binding requests to discover external IP and port mappings and then reports those mappings to public STUN servers for command delivery.
  • Researchers traced a spike in exploit attempts starting around September 5 that delivered Cling variants by abusing a growing catalog of known flaws, including a Realtek Jungle SDK RCE and vulnerabilities in D-Link, EnGenius, Hytec and other vendors.
  • The botnet embeds hardcoded exploits and uses downloaders that fetch payloads for many CPU architectures, including x86_64, ARM, MIPS and PowerPC, allowing wide cross‑device propagation.
  • On infected systems ClingSTUN installs persistent copies, kills competing processes and watchdogs, replaces common binaries to run at boot, and polls STUN transaction ID fields where operators embed remote commands — researchers even observed command packets appearing to come from a Google STUN address.
  • Defenders are advised to inventory and isolate internet-facing IoT and router devices, prioritize patching of actively exploited CVEs, monitor unusual STUN/UDP keepalive patterns and process behavior, and apply compensating controls like microsegmentation or automated firmware remediation when immediate patching is not possible.