Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The analyzed Cling sample contains embedded exploit logic for several additional command-injection vulnerabilities, including Realtek SDK RCE (CVE-2014-8361). | Cling is a botnet delivered through exploitation of CVE-2021-35394 and other IoT device command-injection flaws. It uses STUN-like traffic and public STUN infrastructure for host registration and command-and-control.
The analyzed Cling sample contains embedded exploit logic for TBK DVR RCE (CVE-2024-3721). | Cling is a botnet delivered through exploitation of CVE-2021-35394 and other IoT device command-injection flaws. It uses STUN-like traffic and public STUN infrastructure for host registration and command-and-control.
The analyzed Cling sample contains embedded exploit logic for Linksys RCE (CVE-2025-34037). | Cling is a botnet delivered through exploitation of CVE-2021-35394 and other IoT device command-injection flaws. It uses STUN-like traffic and public STUN infrastructure for host registration and command-and-control.
The analyzed Cling sample contains embedded exploit logic for MVPower CCTV DVR RCE (CVE-2016-20016). | Cling is a botnet delivered through exploitation of CVE-2021-35394 and other IoT device command-injection flaws. It uses STUN-like traffic and public STUN infrastructure for host registration and command-and-control.
The analyzed Cling sample contains embedded exploit logic for FiberHome SR1041F router / China Mobile HG6543C4 RCE (CVE-2023-41011). | Cling is a botnet delivered through exploitation of CVE-2021-35394 and other IoT device command-injection flaws. It uses STUN-like traffic and public STUN infrastructure for host registration and command-and-control.
The report observed multiple attempts to exploit CVE-2021-35394, a remote-code-execution vulnerability affecting the Realtek Jungle SDK diagnostic component commonly compiled as UDPServer. Cling was delivered through exploitation of internet-exposed devices. | Cling is a botnet delivered through exploitation of CVE-2021-35394 and other IoT device command-injection flaws. It uses STUN-like traffic and public STUN infrastructure for host registration and command-and-control.
The analyzed Cling sample contains embedded exploit logic for LB-LINK routers RCE (CVE-2023-26801). | Cling is a botnet delivered through exploitation of CVE-2021-35394 and other IoT device command-injection flaws. It uses STUN-like traffic and public STUN infrastructure for host registration and command-and-control.
The analyzed Cling sample contains embedded exploit logic for Eir D1000 router RCE (CVE-2016-10372). | Cling is a botnet delivered through exploitation of CVE-2021-35394 and other IoT device command-injection flaws. It uses STUN-like traffic and public STUN infrastructure for host registration and command-and-control.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Proxy relay: Connects to the provided ip:port relay server and forwards traffic between the relay and compromised device.
Cling receives operator commands over UDP packets sent to NAT-mapped ports learned through STUN-like communication. The commands are encoded in the STUN transaction ID field.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.