Nozomi Networks noticed a spike in exploitation attempts against an old Realtek SDK flaw in early September 2026 and found a botnet behind some of it. Fortinet published its own analysis of the same malware on 5 October, under the name ClingSTUN.

The interesting part is not how it gets in. It is how it talks once it is there.

A command channel made of NAT traversal

STUN is the Session Traversal Utilities for NAT. Its entire purpose is to let a device behind a home router discover what its public address and port look like from the outside, so that two machines behind two routers can find each other. Every video call, every VoIP phone and most peer-to-peer software depends on it, and there are public STUN servers run by large providers for anyone to use.

Cling uses it as its command channel.

The implant opens a UDP socket on a random local port and sends standard 20-byte STUN binding requests to a list of public STUN endpoints. Fortinet traced the list tightening across versions: an earlier build used 24 endpoints and accepted the result if at least half answered; a later one cut to 13 and required every one to succeed. The replies tell the implant its externally mapped ports, and the repetition keeps the router's NAT mapping alive.

Then it sends its group identifier and its list of mapped ports back to those same endpoints, and waits. A 20-byte packet from the operator triggers the rest: one command opens an outbound TCP connection over which remote commands arrive and run.

Every packet in that description is a legitimate STUN exchange, going to legitimate public servers, from a device that has an ordinary reason to do exactly this.

Why that is hard to filter

Network detection works by asking whether a host is talking to somewhere it should not be. Cling's answer is no.

The destinations are public infrastructure operated by large providers, including Google's. Blocking them breaks video calling. The protocol is UDP on a well-known port that is already permitted outbound in almost every network, because it has to be. And the traffic shape — short binding requests at an interval, keeping a mapping warm — is precisely what an uninfected VoIP handset does all day.

Fortinet is careful about one gap, and it is worth repeating because it is the hinge: how the operator learns the device's external mapping in order to send that trigger packet is not verified. The researchers describe what the implant does and stop short of claiming they have seen the other half.

The third one this fortnight

This is now a pattern we have written about three times in two weeks, and it is worth naming as one idea rather than three incidents.

The Antino backdoor polls an Outlook mailbox and leaves files in OneDrive, so every packet goes to Microsoft. North Korean operators put payloads in smart contracts and fetch them with read-only calls that leave no transaction. Cling puts its rendezvous in STUN.

Three different actors, three different substrates, one shared conclusion: a command channel is only as durable as the willingness of someone to take it down, so build it out of something nobody will. The era of a C2 being an IP address on a blocklist is ending, and the detections that depend on destination reputation are ending with it.

Old holes, new tenant

The way in is the opposite of novel.

Nozomi's spike was against a Realtek SDK flaw scored 9.8 and patched years ago. Fortinet lists initial access through vulnerabilities in Hytec routers, EnGenius devices and D-Link UPnP, and seven more hardcoded for spreading — including a Realtek bug from 2014 and an MVPower CCTV flaw from 2016. TP-Link, Tenda, AVTECH, Linksys and others appear in the target list.

Persistence is equally plain: the binary copies itself to two hidden paths and appends itself to the boot scripts of SysV and BusyBox init, which is what you do when your victims are devices nobody logs into.

That combination is the story of consumer and small-business network gear. The sophistication goes into the channel, because the entry never needs any — the twelve-year-old vulnerability is still there, on a device with no update mechanism and no owner who thinks of it as a computer.

What to do

  • Inventory what is actually on your edge. Routers, DVRs, cameras and access points bought by someone who has left, installed by a contractor, or inherited with the building.
  • Take management interfaces off the internet, and turn off UPnP where it is not needed. Several of the entry points here are exposed device administration.
  • Look for the persistence rather than the traffic. Hidden files named for the malware in the root and local binary directories, and unexpected entries appended to the boot scripts, are far easier to find than STUN packets are.
  • If you can, baseline which hosts legitimately speak STUN. A camera or a DVR doing NAT traversal has no business reason to; a desk phone does.
  • Replace anything whose vendor stopped shipping firmware. For a device carrying a 2014 flaw, there is no patch to apply.

What is not established

  • How the operator obtains the external mapping needed to reach an infected device. Fortinet explicitly does not claim to have verified it.
  • How large the botnet is.
  • Who operates it, which neither analysis attributes.
  • Whether the three operational phases Fortinet describes are one actor iterating or a tool passing between hands.