Researchers Identified New Cling IoT Botnet

The malware hides command-and-control traffic by mimicking Google's public STUN infrastructure.

Updated on Oct. 3, 2026 in Cybersecurity

Bold flat-color editorial illustration in navy, cream, and red, depicting a stylized industrial network appliance, evoking cybersecurity threat infrastructure.
Nozomi Networks Labs discovered the Cling IoT botnet, a new threat that masks command-and-control communications by mimicking legitimate STUN protocol traffic. AI Illustration. Upload story photo >

Live Poll

Do you trust that your connected smart devices are secure from unauthorized digital access?

Nozomi Networks Labs has identified the Cling IoT botnet, a new threat that targets internet-facing devices. The malware effectively masks its command-and-control communications by disguising them as routine STUN traffic.

Why it matters

This technique allows attackers to maintain persistent control over compromised IoT hardware while avoiding detection by blending malicious activity into expected network traffic. It highlights the ongoing challenge of securing internet-exposed devices against sophisticated obfuscation methods.

The Cling botnet uses STUN (Session Traversal Utilities for NAT) packets to bypass security filters. By crafting traffic to mimic legitimate requests to Google public STUN infrastructure, the malware hides its command-and-control signaling within routine network traversal processes.

The players

Nozomi Networks Labs

A cybersecurity research division focused on identifying vulnerabilities and threat campaigns within industrial control systems and IoT environments.

The details

The Cling malware specifically targets internet-facing IoT devices by exploiting NAT-traversal protocols. NAT, or Network Address Translation, is a method used to map multiple local network addresses to a single public IP address. By disguising its communications as STUN packets—a standard protocol used to assist devices in discovering their public IP addresses—the malware blends its malicious traffic into legitimate background noise.

Timeline

  1. October 3, 2026: Nozomi Networks Labs published the report detailing the discovery of the Cling botnet.

The Tech Race

The Cling botnet follows the long-standing pattern of weaponizing exposed internet-facing IoT devices first established by the Mirai botnet discovery. It represents a further evolution in how attackers hide command-and-control infrastructure within common network protocols.

IoT device administrators should review firewall logs for unusual STUN traffic patterns mimicking Google infrastructure. This threat impacts anyone maintaining internet-facing hardware, requiring heightened scrutiny of outbound network traffic originating from IoT endpoints.

The takeaway

The Cling botnet demonstrates that attackers are increasingly leveraging common protocols to hide malicious traffic in plain sight. Security teams should prioritize monitoring NAT-traversal traffic patterns to identify potential command-and-control activity on their networks.

Further reading

For broader context on emerging threats targeting connected hardware, visit our Cybersecurity section.

Live Poll

Do you trust that your connected smart devices are secure from unauthorized digital access?