home.social

#cve202135394 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve202135394, aggregated by home.social.

  1. A STUNning Disguise: Cling Malware Masquerades as Google

    A sophisticated IoT botnet dubbed Cling has been discovered exploiting vulnerable internet-exposed devices through CVE-2021-35394 and other command-injection flaws. The malware distinguishes itself by abusing STUN protocol traffic and public STUN infrastructure for command-and-control communications, making malicious activity appear as legitimate NAT-traversal behavior. Cling propagates through multiple CVE exploits targeting routers, DVRs and embedded appliances, establishes persistence via init scripts and wget binary replacement, then communicates with operators through STUN-like exchanges with public servers. The botnet operator uses IP spoofing to make commands appear as if originating from Google's STUN infrastructure. Capabilities include propagation scanning, DDoS flooding, TCP tunneling and proxy relay functions. The malware supports various attack commands hidden within STUN transaction ID fields while maintaining a low detection profile by blending into legitimate application traffic from collab...

    Pulse ID: 6ac368846173b592a85473db
    Pulse Link: otx.alienvault.com/pulse/6ac36
    Pulse Author: AlienVault
    Created: 2026-10-05 09:06:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cling #Google #botnet #CVE202135394 #OTX #AlienVault

Share on Mastodon

Enter the server where you have an account.