October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

What STUN-Based Command-and-Control Means for Router Security

STUN is legitimate, but a Cling sample repurposed STUN-like exchanges for command-and-control. Here are the reported behaviors, indicators, and router-security implications.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

STUN traffic is not, by itself, evidence that a router is infected. But in a Cling MIPS malware sample analyzed by Nozomi Networks Labs and reported on October 1, 2026, STUN-like exchanges helped the malware register infected devices and receive commands hidden in UDP packet transaction IDs. The case matters because ordinary-looking network protocols can be repurposed; defenders need to look for the sample’s unusual behavior and corroborate it with device evidence.

What STUN does—and what it does not tell you

STUN, or Session Traversal Utilities for NAT, helps an endpoint discover the public IP address and port mapping that a server sees through a network address translator. It is also used in legitimate real-time communications, including systems that use ICE or TURN. The IETF’s RFC 8489 defines the protocol and its normal request-and-response behavior.

That means a router or network making STUN connections is not automatically suspicious. The useful question is whether the traffic behaves like ordinary STUN. Nozomi’s report concerns one analyzed Cling sample, not all STUN use, all routers, or every Cling variant.

How the reported Cling sample turned STUN-like traffic into command-and-control

In a normal STUN Binding exchange, a client sends a request and receives a response that reports the public-facing address and port observed by the server. Nozomi described the following sequence in its analyzed sample:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
TP-Link AX1800 WiFi 6 Router (Archer AX21 V5)
  • DUAL-BAND WIFI 6 ROUTER: Wi-Fi 6(802.11ax) technology achieves faster speeds, greater capacity and reduced network congestion compared to the previous gen. All WiFi routers require a separate modem. Dual-Band WiFi routers do not support the 6 GHz band.
  • AX1800: Enjoy smoother and more stable streaming, gaming, downloading with 1.8 Gbps total bandwidth (up to 1200 Mbps on 5 GHz and up to 574 Mbps on 2.4 GHz). Performance varies by conditions, distance to devices, and obstacles such as walls.
  • CONNECT MORE DEVICES: Wi-Fi 6 technology communicates more data to more devices simultaneously using revolutionary OFDMA technology
  • EXTENSIVE COVERAGE: Achieve the strong, reliable WiFi coverage with Archer AX1800 as it focuses signal strength to your devices far away using Beamforming technology, 4 high-gain antennas and an advanced front-end module (FEM) chipset
  • OUR CYBERSECURITY COMMITMENT: TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
  1. The sample periodically sent Binding Requests to a hard-coded list of 13 STUN servers, approximately every five seconds. Its requests used an all-zero transaction ID, unlike the random value expected by the protocol.
  2. It recorded the public IP address and mapped port reported in Binding Success Responses.
  3. It sent custom UDP registration datagrams to the contacted endpoints. These included mapped ports and an infection-method tag, but did not conform to STUN; conforming servers ignored them.
  4. It listened for UDP packets sent to the mapped ports and interpreted data in the STUN transaction-ID field as commands.

Nozomi reported that one endpoint returned an all-zero transaction ID rather than echoing the request’s ID. In a controlled validation, the researchers advertised different port sets to different endpoints, then received commands on a port advertised to the suspect endpoint. They inferred that endpoint was involved in the botnet’s command infrastructure.

The researchers also said command packets appeared to come from an IP address associated with stun.l.google.com, and proposed source-address spoofing as the likely explanation. That observation is not evidence that Google operated the command server.

Rank #2
Sale
TP-Link BE6500 Dual-Band WiFi 7 Router (BE400)
  • 𝐅𝐮𝐭𝐮𝐫𝐞-𝐑𝐞𝐚𝐝𝐲 𝐖𝐢-𝐅𝐢 𝟕 - Designed with the latest Wi-Fi 7 technology, featuring Multi-Link Operation (MLO), Multi-RUs, and 4K-QAM. Achieve optimized performance on latest WiFi 7 laptops and devices, like the iPhone 16 Pro, and Samsung Galaxy S24 Ultra.
  • 𝟔-𝐒𝐭𝐫𝐞𝐚𝐦, 𝐃𝐮𝐚𝐥-𝐁𝐚𝐧𝐝 𝐖𝐢-𝐅𝐢 𝐰𝐢𝐭𝐡 𝟔.𝟓 𝐆𝐛𝐩𝐬 𝐓𝐨𝐭𝐚𝐥 𝐁𝐚𝐧𝐝𝐰𝐢𝐝𝐭𝐡 - Achieve full speeds of up to 5764 Mbps on the 5GHz band and 688 Mbps on the 2.4 GHz band with 6 streams. Enjoy seamless 4K/8K streaming, AR/VR gaming, and incredibly fast downloads/uploads.
  • 𝐖𝐢𝐝𝐞 𝐂𝐨𝐯𝐞𝐫𝐚𝐠𝐞 𝐰𝐢𝐭𝐡 𝐒𝐭𝐫𝐨𝐧𝐠 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧 - Get up to 2,400 sq. ft. max coverage for up to 90 devices at a time. 6x high performance antennas and Beamforming technology, ensures reliable connections for remote workers, gamers, students, and more.
  • 𝐔𝐥𝐭𝐫𝐚-𝐅𝐚𝐬𝐭 𝟐.𝟓 𝐆𝐛𝐩𝐬 𝐖𝐢𝐫𝐞𝐝 𝐏𝐞𝐫𝐟𝐨𝐫𝐦𝐚𝐧𝐜𝐞 - 1x 2.5 Gbps WAN/LAN port, 1x 2.5 Gbps LAN port and 3x 1 Gbps LAN ports offer high-speed data transmissions.³ Integrate with a multi-gig modem for gigplus internet.
  • 𝐎𝐮𝐫 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐨𝐦𝐦𝐢𝐭𝐦𝐞𝐧𝐭 - TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.

How the reported behavior differs from ordinary STUN

Signal Ordinary STUN behavior Behavior reported in the Cling sample
Transaction ID A request uses a random transaction ID, which the response uses to match the exchange (IETF RFC 8489). Binding Requests used an all-zero ID; command data was carried in the transaction-ID field (Nozomi Networks Labs, October 1, 2026).
Traffic purpose Binding exchanges help an endpoint learn its public-facing address and port mapping. Custom UDP registration datagrams advertised mapped ports and an infection-method tag; the sample also listened for commands on mapped ports (Nozomi Networks Labs, October 1, 2026).
Response pattern A response corresponds to the request’s transaction ID. Nozomi reported one endpoint returning an all-zero ID instead of echoing the request’s ID (Nozomi Networks Labs, October 1, 2026).

These are behavioral clues, not a rule that every deviation proves malware. Network equipment, applications, and measurement conditions can affect what defenders observe; investigate the full exchange and the device involved.

Why a compromised router matters

The commands Nozomi identified in the sample could download and execute payloads, scan for and exploit other systems, start or stop a TCP tunnel, start or stop a proxy relay, and launch a denial-of-service flood. A compromised router could therefore serve as an initial foothold, relay, tunnel endpoint, or botnet node—not just as a target whose own traffic is affected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
TP-Link Dual-Band AX3000 Wi-Fi 6 Wireless Gigabit Internet Router for Home
  • Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
  • A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
  • Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
  • Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
  • Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.

Nozomi also reported attempts to exploit CVE-2021-35394, a remote-code-execution flaw in the Realtek Jungle SDK diagnostic component commonly compiled as UDPServer. In its observed example, a UDP datagram beginning with orf; was followed by shell commands that downloaded and ran malware. Realtek SDK components appear in various embedded products, but that does not mean every device using a Realtek component is vulnerable or was compromised.

The analyzed sample contained exploit logic associated with other products and vulnerabilities, including Realtek SDK, LB-LINK routers, TBK DVRs, Linksys, Eir D1000 routers, FiberHome SR1041F/China Mobile HG6543C4, and MVPower CCTV DVRs. The presence of exploit code is not proof of successful exploitation or of a vulnerability in every product from a named vendor.

Rank #4
TP-Link AC1200 Gigabit Dual Band WiFi Router (Archer A6)
  • Dual band router upgrades to 1200 Mbps high speed internet (300mbps for 2.4GHz plus 900Mbps for 5GHz), reducing buffering and ideal for 4K stream
  • Full Gigabit Ports - Gigabit Router with 4 Gigabit LAN ports, ideal for any internet plan and allow you to directly connect your wired devices
  • Boosted Coverage - Four external antennas equipped with Beamforming technology extend and concentrate the Wi-Fi signals
  • MU-MIMO technology - (5GHz band) allows high speeds for multiple devices simultaneously
  • Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What router owners and defenders can investigate

Look for a combination of network behavior and device-side evidence. A single STUN connection—or any one indicator below—does not establish infection.

Network clues

  • Repeated STUN Binding Requests with all-zero transaction IDs.
  • Custom UDP registration datagrams sent to endpoints contacted for STUN.
  • Responses that fail to echo a request’s transaction ID.
  • Unexpected inbound UDP packets arriving at ports learned through the STUN exchanges.

Device clues from the analyzed sample

  • Copies of the malware at /root/.cling or /usr/local/bin/.cling.
  • References to the malware appended to init-related files.
  • A replaced wget executable, with the original preserved and its location recorded; Nozomi lists companion paths wget.r and wget.p as hunting clues.
  • Use of port 33957 for the sample’s single-instance check.

These artifacts are leads specific to the analyzed sample, not guaranteed indicators for every variant. Nozomi recommends reviewing exposed routers, access points, DVRs, and other embedded appliances for relevant vulnerable components, and using indicators and technique mappings to guide investigation. CISA and partner agencies’ broader communications-infrastructure guidance also supports keeping device and firmware inventories, using secure authentication, centralizing logs, and establishing baselines for normal network behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do if the signals appear

  1. Identify the device precisely. Record the manufacturer, exact model, hardware revision, firmware version, and whether its management or diagnostic services are reachable from the internet.
  2. Check the vendor’s guidance for that exact model and firmware. Confirm whether the relevant component and vulnerability apply, and follow the vendor’s remediation instructions. The reporting cited here does not provide a complete model-by-model patch matrix.
  3. Preserve useful evidence. If you manage the network, retain relevant firewall, DNS, and flow logs and document suspicious destinations, ports, timestamps, and device identifiers. Avoid treating a STUN destination alone as proof.
  4. Escalate suspected compromise. For an organization, involve its incident-response team or service provider; for a home router, contact the device vendor or internet provider for model-specific recovery advice. If a device cannot be supported or secured, ask the provider about a supported replacement rather than assuming a factory reset alone resolves the vulnerability.

Nozomi reported a spike in observed attempts and analyzed one MIPS sample, but did not establish a population-wide infection count or prevalence rate. The report’s server count and request interval describe that sample, not how common the activity is across routers.

Quick Recap

SaleBestseller No. 1
TP-Link AX1800 WiFi 6 Router (Archer AX21 V5)
TP-Link AX1800 WiFi 6 Router (Archer AX21 V5)
VPN SERVER: Archer AX21 Supports both Open VPN Server and PPTP VPN Server
$69.99
Bestseller No. 4
TP-Link AC1200 Gigabit Dual Band WiFi Router (Archer A6)
TP-Link AC1200 Gigabit Dual Band WiFi Router (Archer A6)
MU-MIMO technology - (5GHz band) allows high speeds for multiple devices simultaneously
$44.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.