Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices

A newly identified IoT botnet, Cling, disguises its command-and-control traffic as legitimate STUN packets, including ones appearing to come from Google’s public STUN infrastructure. Nozomi Networks Labs found the campaign while investigating compromised internet-facing devices; the technique blends C2 into routine NAT-traversal traffic.

Edward Kiledjian @ekiledjian