[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwoisKgUyhvT_ABWoqFyDhcaoKEurQAA0h541__C1IaU":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"3c969e11-ad7a-449e-b4e7-59e0d416f9f5","Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2","realtek-jungle-sdk-exploit-attempts-deliver-cling-botnet-with-stun-based-c2-b5ce63","Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. \"Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel,\" Nozomi Networks said in a report","Threat actors have been observed exploiting CVE-2021-35394, a critical RCE flaw in Realtek Jungle SDK, to deploy the Cling botnet malware. Cling is notable for repurposing STUN (Session Traversal Utilities for NAT) protocol traffic into a command-and-control channel, making malicious activity appear as legitimate NAT-traversal communication. The malware embeds exploit logic for multiple router and DVR vulnerabilities and achieves persistence through various mechanisms including self-copying and wget binary replacement.","Cling botnet exploits patched Realtek Jungle SDK flaw, uses STUN protocol for C2.","Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 Ravie LakshmananOct 05, 2026Vulnerability \u002F Malware Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. \"Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel,\" Nozomi Networks said in a report published last week. \"The result is a botnet whose traffic can resemble legitimate NAT-traversal activity while still supporting propagation, proxying, tunneling and denial-of-service commands.\" The operational technology (OT) security company said it observed a spike in attempts to exploit CVE-2021-35394 (CVSS score: 9.8), a critical remote code execution (RCE) flaw in Realtek Jungle SDK starting around September 5, 2026, with a subset of the activity delivering Cling. An analysis of the malware sample has found it to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors - Realtek SDK RCE (CVE-2014-8361) Eir D1000 router RCE (CVE-2016-10372) MVPower CCTV DVR RCE (CVE-2016-20016) LB-LINK routers RCE (CVE-2023-26801) FiberHome SR1041F router \u002F China Mobile HG6543C4 RCE (CVE-2023-41011) TBK DVR RCE (CVE-2024-3721) Linksys RCE (CVE-2025-34037) \"The single-instance check to only run one copy involves binding a socket with SO_REUSEADDR to port 33957 and exiting cleanly if it fails,\" Nozomi Networks said. \"The sample copies itself to \u002Froot\u002F.cling and \u002Fusr\u002Flocal\u002Fbin\u002F.cling. Both executables are appended to \u002Fetc\u002Finittab, \u002Fetc\u002Finit.d\u002FrcS, \u002Fetc\u002Frc.d\u002Frc.boot, thus achieving persistence on SysV and BusyBox init systems.\" An alternative persistence mechanism involves identifying the wget binary on the infected system and then replacing it with the malware, but not before moving the original to another location. This, in turn, causes the malware to be executed when a legitimate process invokes the \"wget\" command. A notable aspect of Cling is its abuse of harmless-looking STUN traffic and public STUN infrastructure to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective. STUN, short for Session Traversal Utilities for Network Address Translation (NAT), is a standardized network protocol that's designed to assist devices behind a NAT or firewall in establishing peer-to-peer real-time communications. Specifically, the malware follows a four-step process for command-and-control (C2) communications - Send a STUN Binding Request to a hard-coded list of 13 STUN servers roughly every 5 seconds. The transaction ID is set to all zeros instead of a random value, as per the specification. Record the externally observed ports returned by those servers upon receiving a Binding Success Response message containing the public IP address of the endpoint and the associated port numbers. Sends a custom registration message (i.e., a UDP datagram) to each server that includes the mapped ports and a tag denoting how the device was infected (e.g., realtek.selfrep, selfrep.router). Poll for UDP packets that encode operator commands in the STUN transaction ID field. \"From a network monitoring perspective, the activity appears as innocuous interaction with STUN servers,\" Nozomi Networks said. \"Given that the custom registration message is sent to every STUN server in the list, it is apparent that the operator requires visibility into at least one of the servers, in order to track new bots joining the swarm to know where to send commands to.\" It's worth noting these registration messages do not conform to the STUN protocol definition, causing legitimate STUN servers to drop the packet. However, one of the 13 servers (\"145.249.115[.]184\") is said to have returned an all-zero transaction ID instead of echoing the transaction ID of the original Binding Request in the Binding Success Response. This unusual behavior, per Nozomi, suggests the STUN server is tailored to the bot's own STUN traffic and that it's used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field. The commands allow the threat actor to recursively scan and spread the scale of the botnet in a worm-like fashion, spawn\u002Fstop a TCP tunnel, launch\u002Fstop a proxy, and perform a denial-of-service (DoS) attack against a specified target for a given time duration. Some of the targets of the flooding attacks are below - 112.151.157[.]222:8080 (South Korean ISP) 192.170.240[.]137:53 (University of Chicago cluster) 23.81.40[.]193:25565 (Minecraft) 147.185.221[.]129:25565 (Minecraft) \"The most interesting part of the C2 traffic is where the commands appeared to come from,\" Nozomi Networks explained. \"The packets carrying operator commands originate from 74.125.250[.]129, an IP address that stun.l.google.com resolves to.\" \"In other words, the operator is not merely hiding commands inside a STUN-looking packet, but they are making those commands appear as if they are legitimate replies from one of the most recognizable STUN services on the internet.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  botnet, iot security, Malware, network security, Vulnerability ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Frealtek-jungle-sdk-exploit-attempts.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgeczuQyi5eCbsZFxILJKWiHZ8_JC8gnKqr2sExCgq_Dk-7879VVbd8qcA475L-uEn3X30CIyqn-iDilE7Sl9T5FM3XGFPU6LbyE7KUH8OpWTjlirCFq8EaY-MuielVGOXFuECLLpehX9R8HQrniMulUnAUd2f_uRbZ1Fget8hT0Tf19c1N-q06dtFpAZPj\u002Fs1600\u002Fbotnet.jpg","2026-10-05T11:46:25+00:00","2026-10-05T14:00:21.337143+00:00",9,[18,21,24,26],{"name":19,"type":20},"Realtek Jungle SDK","product",{"name":22,"type":23},"Realtek","vendor",{"name":25,"type":23},"Nozomi Networks",{"name":27,"type":28},"STUN","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":29,"icon":31,"name":32,"slug":33},null,"Malware","malware",[35,40,45],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":41},{"id":42,"icon":31,"name":43,"slug":44},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":46},{"id":47,"icon":31,"name":48,"slug":49},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",[51,55,58,61,64,67,70,73,76,79],{"type":52,"value":53,"context":54},"cve","CVE-2021-35394","Critical RCE in Realtek Jungle SDK (CVSS 9.8), exploited starting September 5, 2026",{"type":52,"value":56,"context":57},"CVE-2014-8361","Realtek SDK RCE, embedded in Cling malware",{"type":52,"value":59,"context":60},"CVE-2016-10372","Eir D1000 router RCE, embedded in Cling malware",{"type":52,"value":62,"context":63},"CVE-2016-20016","MVPower CCTV DVR RCE, embedded in Cling malware",{"type":52,"value":65,"context":66},"CVE-2023-26801","LB-LINK routers RCE, embedded in Cling malware",{"type":52,"value":68,"context":69},"CVE-2023-41011","FiberHome SR1041F router \u002F China Mobile HG6543C4 RCE, embedded in Cling malware",{"type":52,"value":71,"context":72},"CVE-2024-3721","TBK DVR RCE, embedded in Cling malware",{"type":52,"value":74,"context":75},"CVE-2025-34037","Linksys RCE, embedded in Cling malware",{"type":33,"value":77,"context":78},"Cling","Botnet malware using STUN protocol for C2, deployed via Realtek SDK exploitation",{"type":80,"value":81,"context":82},"ip","145.249.115.184","STUN server used for C2 communication, returns all-zero transaction ID"]