Researchers have reported on Cling malware, which targets vulnerable Realtek-based devices and disguises command-and-control traffic as Google STUN responses while building an IoT botnet. The reported behavior is a reminder that protocol-looking traffic is not automatically benign when it appears in unexpected contexts.
Defenders responsible for connected devices should identify exposed Realtek-based equipment, apply available vendor updates, and remove unnecessary internet exposure. Network teams can also baseline legitimate STUN use, investigate unusual destinations or volumes, and segment IoT devices from sensitive systems.
Because IoT remediation can be constrained by unsupported hardware and inconsistent vendor patching, compensating controls matter: restrict inbound management access, use egress filtering where feasible, rotate default or weak credentials, and monitor devices for configuration changes or suspicious outbound connections.
Source: CybersecurityNews.
