Nozomi Networks Labs has identified a botnet dubbed Cling that exploits internet-exposed IoT and networking devices and disguises its command-and-control traffic as legitimate STUN activity.

Cling’s command-and-control design uses STUN-like exchanges to register infected devices and deliver operator commands, allowing the traffic to resemble normal NAT-traversal activity commonly generated by collaboration tools, browsers and real-time communications applications.

This visibility helps us track exploitation trends and identify cases where routine-looking activity leads to more interesting malware behavior,” Nozomi researchers detailed in a post last week.

During that time, the operator repeatedly tasked infected devices with spreading across the internet by scanning for and attacking vulnerable systems.

In conclusion, the Nozomi researchers identified that Cling shows how commodity IoT botnets are evolving beyond familiar Mirai-like patterns.