Contents

Cling Botnet Turns Home Routers and Video Recorders Into Hidden Proxies Behind a Fake Google Address

 

Ethical Hacking Complete Course Zero to Expert

Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.

→ Take the full course
 
Contents

Home routers from Linksys, TP-Link, D-Link and Tenda are being turned into hidden proxies, and the orders arrive disguised as Google. The owners did nothing wrong. 32 holes, the main one from 2021.

Once the malware is on a device, the operators decide what it does next. It can carry their traffic out through the owner’s internet connection, open a port that accepts connections from the outside, scan for the next vulnerable device, or flood a target with traffic.

And there is one command underneath all of that which matters more than the rest. On a word from the operators, the device downloads a program from an address they pick and runs it. Whatever they send to it runs. A proxy today, something else next week, on a box the owner believes is only handing out the WiFi.

That proxy job is the reason a home router is worth breaking into at all. A proxy is a machine that passes traffic along for someone else. When an attacker routes their work through a hacked router in a living room, the website on the other end sees the address of that household, not the attacker’s. A scan, a login attempt, a complaint from someone who got attacked, all of it points back at the family in that house. I wrote in August about Evooo1Bot, a botnet that rented out home routers in much the same way. Cling does that too.

Two companies pulled it apart within days of each other. Nozomi Networks Labs published first, on October 1, and named the malware Cling. FortiGuard Labs followed on October 5 with a second write-up by Vincent Li, who calls it ClingSTUN. The researchers at Nozomi did more than read the code. For several days they watched the commands the operators handed out and wrote down what came in. The orders were to scan the internet and break into more devices, and to flood four targets: a South Korean internet provider, a research cluster at the University of Chicago, and two Minecraft servers.

Fortinet watched the campaign change shape as they tracked it. The first wave came in through a router from Hytec Inter and lasted two days. Then the operators moved to another download server and switched to other ways in, a hole in a cloud service from EnGenius and one in a D-Link device, and they kept adding more. Fortinet says plainly it is still evolving as they write. Someone is keeping it alive and adding to it as they go.

The main way in starts at Realtek, the company that makes the chips inside a lot of this hardware. Realtek hands its customers a software kit to build routers, repeaters and cameras around those chips, and inside that kit is a little diagnostic service, normally built as a program called UDPServer. It listens on the network and takes what it is sent. Realtek added a check to it: the service only acts if the message begins with three letters, orf. In 2021 the researchers at ONEKEY showed that this check holds nothing back. You send orf, a semicolon, then whatever command you want, and the device runs it with full rights and never asks for a password. The three letters are still at the front, so the check is happy. That is all it looks at.

This reaches well beyond routers. The same Realtek kit sits inside WiFi repeaters, IP cameras and smart-lighting hubs, and ONEKEY even found it in internet-connected toys. Any of those, still plugged in and still listening on the network, is a door.

ONEKEY counted at least 65 vendors shipping that kit inside their products. Palo Alto Networks’ Unit 42 later found the bug in almost 190 device models from 66 manufacturers, and by December 2022 had logged 134 million attempts to exploit it. It is CVE-2021-35394, scored 9.8 out of 10, and CISA has listed it as exploited since December 2021. None of that is new. What is new is that Cling sends that same orf string today and it still works, because the kit is baked into hundreds of thousands of boxes that will never get an update.

Realtek has an older hole in the same kit, in the part that handles UPnP, the feature that lets devices on a home network find each other without the owner setting it up. That one was published back on May 1, 2015, as CVE-2014-8361, and Cling carries an exploit for it too. It landed on that same CISA list in September 2023, eight years after it went public, which tells you how long these things stay useful.

Add up both reports and the campaign uses 32 separate holes. The operators use most of them to break in, and the malware itself carries about eight, the ones it needs to spread from one box to the next. In a normal house that list means TP-Link Archer routers, Tenda gear, Linksys routers, network storage boxes, and video recorders from brands like MVPower and TBK, the kind of DVR sitting under a shop counter. Further down the list are things you find in offices, like Ivanti VPN gateways and Lantronix device servers.

It does not care which of these it lands on. The same malware comes in versions for ARM, MIPS, PowerPC and Intel chips, so one campaign runs on a plastic home router, a camera and a full server without changing a thing.

Two of those holes are much older than their official numbers. In February 2014 Johannes Ullrich at the SANS Internet Storm Center wrote up a worm called TheMoon that was taking over Linksys home routers through a script sitting open on port 8080, no login needed. That hole only got a CVE number in June 2025, eleven years later. The second lives in KGUARD video recorders. Back in July 2021 the researchers at Netlab 360 reported a Mirai variant had been using it since that June, and found at least 3,000 of those recorders online wide open. Its number, CVE-2026-87827, was only published on September 9 this year. A bug stays dangerous as long as a device somewhere still answers it.

What sets Cling apart is how the operators reach it once it is inside, and it rides on a tool you use without thinking. When you start a call in Teams or Zoom, your computer sits behind your router, where the outside world cannot see it directly. So before the call connects, it asks a STUN server out on the internet a simple question: what address and port do you see me on? The server answers, the two ends learn how to find each other, and the call goes through. This happens all day, from Teams, Zoom, Webex and browsers, so a little more of it on the network draws no attention.

Cling hides inside that. Around five seconds apart it sends a STUN request to a list of 13 STUN servers, then sends each of them a small message with the ports it picked up and a tag that says how it got infected. The answers it waits for carry the operator’s orders, tucked into a part of the reply called the transaction ID. In a normal exchange that field is only a random number, a label the standard says must be random. Cling fills those 12 bytes with the command and its settings instead, and its own requests go out with a transaction ID of all zeros, which no ordinary program would do.

The orders appear to come from Google itself. They arrive from 74.125.250.129, the address behind stun.l.google.com, one of the best known STUN servers there is. The researchers do not believe they really come from Google. They looked at the TTL, a small counter in each reply that drops by one at each step it travels, so you can roughly tell how far it came. The packets carrying commands kept arriving with a different TTL than Google’s own answers. Same sender on the label, different distance travelled. That is the mark of a forged sender address, sent from a network that does not check whether the return address on its outgoing traffic is genuine. Many do not: CAIDA’s Spoofer project tested 747 networks over the past year and found 135 that let forged addresses walk straight out, and nearly 60 more that let some through. A packet claiming to be Google, arriving right after your device was doing STUN, slides past the hard look an unknown server would get.

A home router only lets a reply in if something inside reached out first. That is why the bot keeps calling out at short intervals: each STUN request props open a small, short-lived gap for the answer to come back through, tied to the address it was talking to. Keep calling Google, and that gap stays open. A packet with its address forged on it walks right in, because to the router it looks like the answer the device was waiting for.

The operators chose those particular servers with care. Twelve of the 13 are ordinary public STUN servers, most of them on public lists, the same kind a video app reaches for. Blocking them all would break the VoIP and WebRTC apps that lean on them, and Google’s address is used by plenty of legitimate software besides.

Someone still has to send the orders, and here the two reports split. Fortinet said plainly it could not prove how the operator reaches a device tucked behind a home router. Nozomi worked it out. They noticed one of the 13 servers, at 145.249.115.184, answered oddly: it sent back a transaction ID of all zeros, where a normal server echoes back whatever ID you sent it. So they built a client that pretended to be a fresh infection and told each of the 13 servers a different set of ports, a different story to each one. A few hours later, commands came back on a port they had given to that one suspicious server and no other. That server was in on it.

Once Cling is on a box it settles in. It drops copies of itself into two hidden files and writes itself into the startup scripts, so it comes back after a reboot. Then it does something clever with wget, the little program these devices lean on to download things. Cling renames the genuine wget, keeps a note of where it went, and takes its place. After that, whenever a scheduled job, an administrator, or even a rival attacker runs wget, they run Cling, which quietly passes the download to the original so nothing looks broken.

It also hides from whoever logs in to check. It wipes its own command line so it shows up as a blank entry in the process list, and when it runs as root it dresses itself up as the very first process the system started at boot. It switches off the watchdog, the timer that reboots a frozen device, so it cannot be knocked loose that way, and it hunts down and kills competing malware on the same box, because it wants the machine to itself. When it speaks HTTP it even introduces itself: the User-Agent reads clingwashere, so it shows up in your network logs too.

The chip maker patched its kit back in June 2021. The catch is that a fix from Realtek only reaches your router if the brand that built it rolls out a firmware update, and for a lot of these boxes that never happens. D-Link has already listed its DNS-320, DNS-325 and DNS-340L storage drives as end of life, which means no more updates and a plain instruction to throw them out. Neither report puts a number on how many devices are infected right now, and I would rather tell you that than invent one.

So, the box in your hallway. Look up its exact model and its end-of-support date on the maker’s own site. If it is still supported, install the latest firmware today. If the maker has walked away from it, no setting on the admin page will save it, and the plain answer is to replace it. Turn off any admin page or service that can be reached from the internet, since that is the door all of this comes through. If you can set rules on your router or firewall, block 145.249.115.184. And on a Linux-based device where you have a shell, you can look for the traces Cling leaves behind:

1
2
3
ls -la /root/.cling /usr/local/bin/.cling
ls -la /bin/wget.* /usr/bin/wget.* /sbin/wget.* /usr/sbin/wget.* /usr/local/bin/wget.*
grep cling /etc/inittab /etc/init.d/rcS /etc/rc.d/rc.boot

Neither report puts a name or a country on the people behind this, and that restraint is right. In cybersecurity, attribution is one of the hardest problems there is. What we know for sure is how the malware works, not who runs it.

If you want to see this kind of thing with your own eyes instead of taking my word for it, you can. Open up the traffic on your own network and watch which devices talk to which servers out there, and how often, and that is where the one that does not belong starts to stand out. My Ethical Hacking Complete Course Zero to Expert takes you there step by step: reconnaissance, scanning, exploitation and traffic analysis, hands-on, from your first day with no Linux or hacking background.

→ Join my complete ethical hacking course

Hacking is not a hobby but a way of life.

Sources:

Nozomi Networks Labs | FortiGuard Labs | ONEKEY Realtek SDK Advisory | CISA Known Exploited Vulnerabilities Catalog

 
NEWSLETTER

Stay updated

Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.

By Bulls Eye

Jolanda de koff • email • donate

My name is Jolanda de Koff and on the internet, I'm also known as Bulls Eye. Ethical Hacker, Penetration tester, Researcher, Programmer, Self Learner, and forever n00b. Not necessarily in that order. Like to make my own hacking tools and I sometimes share them with you. "You can create art & beauty with a computer and Hacking is not a hobby but a way of life ...

I ♥ open-source and Linux