<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>STUN · Diary of a Lost Honeypot</title><link>https://blog.efespain.com/en/tags/stun/</link><description>A honeypot in some corner of the network. Every infection, a story worth telling.</description><generator>Hugo</generator><language>en</language><managingEditor>eFeSpain</managingEditor><webMaster>eFeSpain</webMaster><copyright>2026 eFeSpain</copyright><lastBuildDate>Tue, 01 Sep 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://blog.efespain.com/en/tags/stun/index.xml" rel="self" type="application/rss+xml"/><item><title>A Mirai that couldn't attack?</title><link>https://blog.efespain.com/en/chapter-19/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-19/</guid><description>I pulled down the three binaries from the previous chapter expecting the usual DDoS arsenal. It wasn't there: not one attack function. What it does instead —and above all, the channel its orders arrive on— is the strangest thing that has come through the honeypot. A bug designed, top to bottom, not to be seen.</description></item><item><title>Twelve alibis and a mailbox</title><link>https://blog.efespain.com/en/chapter-20/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-20/</guid><description>The previous chapter left a question the binary doesn't answer: of the thirteen STUN servers Cling beacons to, one has to be the operator's mailbox —because the bot announces its ports only to those thirteen, to nobody else— and yet all thirteen look like innocent VoIP providers. I didn't catch it issuing an order; I found it by elimination and exclusivity, using public records to see who talks to each one. Twelve have an alibi. The thirteenth doesn't.</description></item></channel></rss>