Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2: A Threat to Internet Security




The recent discovery of a botnet malware called Cling, which has been linked to the exploitation of a critical security flaw in the Realtek Jungle SDK, has sent shockwaves throughout the cybersecurity community. The botnet is notable not only for its ability to repurpose ordinary STUN behavior into a practical command-and-control channel but also for its use of STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective. The Cling malware has been observed to follow a four-step process for command-and-control (C2) communications, which includes sending a STUN Binding Request to a hard-coded list of 13 STUN servers, recording the externally observed ports returned by those servers, sending a custom registration message to each server, and polling for UDP packets that encode operator commands in the STUN transaction ID field. The unusual behavior of one of the 13 STUN servers suggests that it is tailored to the bot's own STUN traffic and is used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field. The Cling malware has been linked to various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors, and has been observed to use the STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective.

  • The Cling botnet malware has been linked to a critical security flaw in the Realtek Jungle SDK.
  • The malware exploits the CVE-2021-35394 vulnerability, which has a CVSS score of 9.8.
  • The Cling botnet uses STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from network monitoring.
  • The malware has been found to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors.
  • The malware uses a four-step process for command-and-control (C2) communications, including sending STUN Binding Requests and custom registration messages.
  • The Cling malware has been observed to send UDP packets that encode operator commands in the STUN transaction ID field.
  • The malware has been linked to various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors.
  • The malware uses persistence mechanisms, including appending itself to init system files and replacing the wget binary, to achieve long-term infection.



  • The recent discovery of a botnet malware called Cling, which has been linked to the exploitation of a critical security flaw in the Realtek Jungle SDK, has sent shockwaves throughout the cybersecurity community. According to recent reports, threat actors have been attempting to exploit this vulnerability,CVE-2021-35394, which has a CVSS score of 9.8, to deploy the Cling botnet. The botnet is notable not only for its ability to repurpose ordinary STUN behavior into a practical command-and-control channel but also for its use of STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective.

    The operational technology (OT) security company, Nozomi Networks, observed a spike in attempts to exploit the CVE-2021-35394 vulnerability starting around September 5, 2026, with a subset of the activity delivering Cling. An analysis of the malware sample has found it to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware follows a four-step process for command-and-control (C2) communications:

    1. Send a STUN Binding Request to a hard-coded list of 13 STUN servers roughly every 5 seconds. The transaction ID is set to all zeros instead of a random value, as per the specification.
    2. Record the externally observed ports returned by those servers upon receiving a Binding Success Response message containing the public IP address of the endpoint and the associated port numbers.
    3. Sends a custom registration message (i.e., a UDP datagram) to each server that includes the mapped ports and a tag denoting how the device was infected (e.g., realtek.selfrep, selfrep.router).
    4. Poll for UDP packets that encode operator commands in the STUN transaction ID field.

    The malware uses the STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective. The Cling malware follows a four-step process for command-and-control (C2) communications. The threat actors are using the STUN protocol to their advantage to make their malicious activity less detectable from network monitoring tools. However, the unusual behavior of one of the 13 STUN servers suggests that it is tailored to the bot's own STUN traffic and is used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field.

    The Cling malware has been found to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to bind a socket with SO_REUSEADDR to port 33957 and exit cleanly if it fails. The sample copies itself to /root/.cling and /usr/local/bin/.cling. Both executables are appended to /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot, thus achieving persistence on SysV and BusyBox init systems. An alternative persistence mechanism involves identifying the wget binary on the infected system and then replacing it with the malware, but not before moving the original to another location.

    This persistence mechanism causes the malware to be executed when a legitimate process invokes the "wget" command. The malware has also been found to use the STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective. The Cling malware has been observed to send custom registration messages to each server that includes the mapped ports and a tag denoting how the device was infected.

    The Cling malware has been linked to various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to send UDP packets that encode operator commands in the STUN transaction ID field. The unusual behavior of one of the 13 STUN servers suggests that it is tailored to the bot's own STUN traffic and is used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field.

    The Cling malware has been found to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to bind a socket with SO_REUSEADDR to port 33957 and exit cleanly if it fails. The sample copies itself to /root/.cling and /usr/local/bin/.cling. Both executables are appended to /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot, thus achieving persistence on SysV and BusyBox init systems. An alternative persistence mechanism involves identifying the wget binary on the infected system and then replacing it with the malware, but not before moving the original to another location.

    This persistence mechanism causes the malware to be executed when a legitimate process invokes the "wget" command. The malware has also been found to use the STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective. The Cling malware has been observed to send custom registration messages to each server that includes the mapped ports and a tag denoting how the device was infected.

    The Cling malware has been linked to various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to send UDP packets that encode operator commands in the STUN transaction ID field. The unusual behavior of one of the 13 STUN servers suggests that it is tailored to the bot's own STUN traffic and is used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field.

    The Cling malware has been found to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to bind a socket with SO_REUSEADDR to port 33957 and exit cleanly if it fails. The sample copies itself to /root/.cling and /usr/local/bin/.cling. Both executables are appended to /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot, thus achieving persistence on SysV and BusyBox init systems. An alternative persistence mechanism involves identifying the wget binary on the infected system and then replacing it with the malware, but not before moving the original to another location.

    This persistence mechanism causes the malware to be executed when a legitimate process invokes the "wget" command. The malware has also been found to use the STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective. The Cling malware has been observed to send custom registration messages to each server that includes the mapped ports and a tag denoting how the device was infected.

    The Cling malware has been linked to various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to send UDP packets that encode operator commands in the STUN transaction ID field. The unusual behavior of one of the 13 STUN servers suggests that it is tailored to the bot's own STUN traffic and is used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field.

    The Cling malware has been found to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to bind a socket with SO_REUSEADDR to port 33957 and exit cleanly if it fails. The sample copies itself to /root/.cling and /usr/local/bin/.cling. Both executables are appended to /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot, thus achieving persistence on SysV and BusyBox init systems. An alternative persistence mechanism involves identifying the wget binary on the infected system and then replacing it with the malware, but not before moving the original to another location.

    This persistence mechanism causes the malware to be executed when a legitimate process invokes the "wget" command. The malware has also been found to use the STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective. The Cling malware has been observed to send custom registration messages to each server that includes the mapped ports and a tag denoting how the device was infected.

    The Cling malware has been linked to various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to send UDP packets that encode operator commands in the STUN transaction ID field. The unusual behavior of one of the 13 STUN servers suggests that it is tailored to the bot's own STUN traffic and is used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field.

    The Cling malware has been found to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to bind a socket with SO_REUSEADDR to port 33957 and exit cleanly if it fails. The sample copies itself to /root/.cling and /usr/local/bin/.cling. Both executables are appended to /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot, thus achieving persistence on SysV and BusyBox init systems. An alternative persistence mechanism involves identifying the wget binary on the infected system and then replacing it with the malware, but not before moving the original to another location.

    This persistence mechanism causes the malware to be executed when a legitimate process invokes the "wget" command. The malware has also been found to use the STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective. The Cling malware has been observed to send custom registration messages to each server that includes the mapped ports and a tag denoting how the device was infected.

    The Cling malware has been linked to various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to send UDP packets that encode operator commands in the STUN transaction ID field. The unusual behavior of one of the 13 STUN servers suggests that it is tailored to the bot's own STUN traffic and is used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field.

    The Cling malware has been found to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to bind a socket with SO_REUSEADDR to port 33957 and exit cleanly if it fails. The sample copies itself to /root/.cling and /usr/local/bin/.cling. Both executables are appended to /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot, thus achieving persistence on SysV and BusyBox init systems. An alternative persistence mechanism involves identifying the wget binary on the infected system and then replacing it with the malware, but not before moving the original to another location.

    This persistence mechanism causes the malware to be executed when a legitimate process invokes the "wget" command. The malware has also been found to use the STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective. The Cling malware has been observed to send custom registration messages to each server that includes the mapped ports and a tag denoting how the device was infected.

    The Cling malware has been linked to various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to send UDP packets that encode operator commands in the STUN transaction ID field. The unusual behavior of one of the 13 STUN servers suggests that it is tailored to the bot's own STUN traffic and is used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field.

    The Cling malware has been found to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to bind a socket with SO_REUSEADDR to port 33957 and exit cleanly if it fails. The sample copies itself to /root/.cling and /usr/local/bin/.cling. Both executables are appended to /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot, thus achieving persistence on SysV and BusyBox init systems. An alternative persistence mechanism involves identifying the wget binary on the infected system and then replacing it with the malware, but not before moving the original to another location.

    This persistence mechanism causes the malware to be executed when a legitimate process invokes the "wget" command. The malware has also been found to use the STUN servers to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective. The Cling malware has been observed to send custom registration messages to each server that includes the mapped ports and a tag denoting how the device was infected.

    The Cling malware has been linked to various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors. The malware has been observed to send UDP packets that encode operator commands in the STUN transaction ID field. The unusual behavior of one of the 13 STUN servers suggests that it is tailored to the bot's own STUN traffic and is used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Realtek-Jungle-SDK-Exploit-Attempts-Deliver-Cling-Botnet-With-STUN-Based-C2-A-Threat-to-Internet-Security-ehn.shtml

  • https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html


  • Published: Mon Oct 5 09:30:29 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us