Overview
- Security firms published detailed analyses on October 5 that show ClingSTUN uses STUN binding requests to discover external IP and port mappings and then reports those mappings to public STUN servers for command delivery.
- Researchers traced a spike in exploit attempts starting around September 5 that delivered Cling variants by abusing a growing catalog of known flaws, including a Realtek Jungle SDK RCE and vulnerabilities in D-Link, EnGenius, Hytec and other vendors.
- The botnet embeds hardcoded exploits and uses downloaders that fetch payloads for many CPU architectures, including x86_64, ARM, MIPS and PowerPC, allowing wide cross‑device propagation.
- On infected systems ClingSTUN installs persistent copies, kills competing processes and watchdogs, replaces common binaries to run at boot, and polls STUN transaction ID fields where operators embed remote commands — researchers even observed command packets appearing to come from a Google STUN address.
- Defenders are advised to inventory and isolate internet-facing IoT and router devices, prioritize patching of actively exploited CVEs, monitor unusual STUN/UDP keepalive patterns and process behavior, and apply compensating controls like microsegmentation or automated firmware remediation when immediate patching is not possible.