The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In October 2026, threat actors exploited CVE-2021-35394, a critical remote code execution vulnerability in Realtek Jungle SDK, to deploy the Cling botnet malware. The malware demonstrated sophisticated command-and-control capabilities by masquerading malicious traffic as legitimate STUN protocol communications, making it appear as routine NAT-traversal activity. Cling infected routers, DVRs, and IoT devices across multiple vendors, establishing persistence through various mechanisms and enabling operators to conduct denial-of-service attacks, proxy operations, and lateral movement. The botnet's innovative use of public STUN infrastructure, including Google's STUN servers, allowed operators to blend malicious communications with legitimate VoIP and WebRTC traffic, significantly complicating detection efforts.

This incident highlights the evolving sophistication of IoT botnets and their ability to exploit legitimate network protocols for covert operations, representing a significant shift in how threat actors conduct command-and-control communications in 2026.

Why This Matters Now

The Cling botnet represents a new evolution in command-and-control obfuscation techniques, demonstrating how threat actors are increasingly leveraging legitimate protocols like STUN to hide malicious activity within normal network traffic, making detection significantly more challenging for traditional security tools.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Cling masquerades malicious C2 communications as legitimate STUN protocol traffic used for NAT traversal, making it appear as routine VoIP or WebRTC communications to evade detection.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would be relevant to this IoT botnet incident by constraining lateral movement between compromised devices and limiting the scope of coordinated attacks through network segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial device compromise would likely still occur, but the blast radius and reachability to other network segments would be constrained through identity-aware network policies

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: While local privilege escalation may still succeed, the scope of access would likely be limited to the immediate device workload without broader network privileges

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral scanning and propagation attempts would likely be constrained by east-west traffic controls, reducing the malware's ability to reach and compromise additional devices

Command & Control

Control: Multicloud Visibility & Control

Mitigation: C2 communications would likely face increased scrutiny and potential blocking through enhanced visibility into traffic patterns and destination controls across cloud environments

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts would likely be constrained through controlled egress policies that limit outbound destinations and inspect traffic for unauthorized data transmission

Impact (Mitigations)

The coordinated attack capability would likely be reduced in scope due to fewer successfully compromised devices and constrained network paths for attack traffic generation

Impact at a Glance

Affected Business Functions

  • Network Infrastructure Management
  • IoT Device Operations
  • Internet Connectivity Services
  • Network Security Monitoring
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: N/A

Data Exposure

Network traffic data, device configuration information, and potentially sensitive communications routed through compromised router and IoT devices acting as proxy nodes in the botnet infrastructure

Recommended Actions

  • • Deploy Inline IPS with signature-based detection to block known exploit patterns targeting IoT device vulnerabilities at network ingress points
  • • Implement Zero Trust Segmentation to isolate IoT devices and prevent lateral movement between network zones using identity-based policies
  • • Enable Egress Security & Policy Enforcement to detect and block unauthorized outbound STUN traffic patterns and command-and-control communications
  • • Establish Multicloud Visibility & Control to identify anomalous IoT device behaviors and suspicious automation patterns across hybrid environments
  • • Activate Threat Detection & Anomaly Response capabilities to baseline normal IoT traffic and alert on deviation from expected communication patterns

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image