Nozomi Networks Labs Identified Cling IoT Botnet

Researchers discovered new malware that masks command-and-control activity as routine Google STUN traffic.

Updated on Oct. 3, 2026 in Cybersecurity

Isometric editorial illustration of cubic nodes and conduits forming a digital network, representing cybersecurity monitoring of internet-facing devices.
Nozomi Networks Labs has uncovered the Cling IoT botnet, which evades detection by masquerading its malicious command-and-control traffic as standard STUN network communications. AI Illustration. Upload story photo >

Live Poll

Do you trust that your connected smart devices are secure from unauthorized digital access?

Nozomi Networks Labs has identified a new IoT botnet called Cling that targets internet-facing devices. The malware disguises its command-and-control communications by mimicking packets from Google public STUN infrastructure.

Why it matters

This technique allows attackers to maintain control over compromised devices while effectively blending malicious activity into legitimate network traffic. By masking signals as routine NAT-traversal traffic, the botnet makes detection significantly more difficult for security teams.

The Cling malware specifically engineers its command-and-control traffic to mimic the signature of packets originating from Google public STUN infrastructure. This method enables the botnet to hide malicious signals within routine network communications used for NAT traversal.

The players

Nozomi Networks Labs

This is a specialized cybersecurity research organization that focuses on monitoring and analyzing threats to internet-connected devices and industrial control systems.

The details

The malware targets internet-facing IoT devices by blending its administrative traffic into standard network flows. By impersonating Google's STUN protocol, the botnet bypasses traditional traffic inspection and makes it difficult to differentiate between malicious control commands and normal device functionality.

Timeline

  1. October 3, 2026: The discovery report regarding the Cling botnet was published.

The Tech Race

The Cling botnet represents a sophisticated evolution in the ongoing arms race between malware developers and network security protocols. By co-opting the Session Traversal Utilities for NAT (STUN) protocol, this malware creates a new challenge for existing traffic filtering and intrusion detection systems.

Users of internet-facing IoT devices may face heightened risks as this botnet specifically targets systems exposed to the public internet. Organizations should review their network traffic for anomalous STUN packet patterns to ensure their devices have not been compromised by this new campaign.

The takeaway

Maintaining robust security for internet-facing hardware is essential to prevent unauthorized remote access. Network administrators should prioritize monitoring for suspicious traffic flows that masquerade as legitimate protocol communications.

Further reading

For more information on current threats and defensive tactics, visit the Cybersecurity section.

Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.

Live Poll

Do you trust that your connected smart devices are secure from unauthorized digital access?