Close Menu
NCIJ Network NCIJ Network
    What's Hot

    How ProPublica Reporters Became Private School Owners in 24 Hours — ProPublica

    October 6, 2026

    Europe’s Chance to Revive the Israeli-Palestinian Peace Process

    October 6, 2026

    Samoa leader apologises for Nazi salute after video from 2007 emerges

    October 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How ProPublica Reporters Became Private School Owners in 24 Hours — ProPublica
    • Europe’s Chance to Revive the Israeli-Palestinian Peace Process
    • Samoa leader apologises for Nazi salute after video from 2007 emerges
    • OpenAI will start watermarking ChatGPT’s text in the EU
    • Meet Together Link: A Free CLI That Runs Open Models Like Kimi K3 and GLM 5.3 Inside Claude Code, Codex, and OpenCode
    • Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
    • Bitcoin treasury Strive risks cash reserve to fund $500M buyback and trim dividends
    • This mysterious hole on the Moon may open into a giant cave
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, October 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 6, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling.

    “Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel,” Nozomi Networks said in a report published last week. “The result is a botnet whose traffic can resemble legitimate NAT-traversal activity while still supporting propagation, proxying, tunneling and denial-of-service commands.”

    The operational technology (OT) security company said it observed a spike in attempts to exploit CVE-2021-35394 (CVSS score: 9.8), a critical remote code execution (RCE) flaw in Realtek Jungle SDK starting around September 5, 2026, with a subset of the activity delivering Cling.

    An analysis of the malware sample has found it to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors –

    “The single-instance check to only run one copy involves binding a socket with SO_REUSEADDR to port 33957 and exiting cleanly if it fails,” Nozomi Networks said. “The sample copies itself to /root/.cling and /usr/local/bin/.cling. Both executables are appended to /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot, thus achieving persistence on SysV and BusyBox init systems.”

    Cybersecurity

    An alternative persistence mechanism involves identifying the wget binary on the infected system and then replacing it with the malware, but not before moving the original to another location. This, in turn, causes the malware to be executed when a legitimate process invokes the “wget” command.

    A notable aspect of Cling is its abuse of harmless-looking STUN traffic and public STUN infrastructure to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective.

    STUN, short for Session Traversal Utilities for Network Address Translation (NAT), is a standardized network protocol that’s designed to assist devices behind a NAT or firewall in establishing peer-to-peer real-time communications.

    Specifically, the malware follows a four-step process for command-and-control (C2) communications –

    • Send a STUN Binding Request to a hard-coded list of 13 STUN servers roughly every 5 seconds. The transaction ID is set to all zeros instead of a random value, as per the specification.
    • Record the externally observed ports returned by those servers upon receiving a Binding Success Response message containing the public IP address of the endpoint and the associated port numbers.
    • Sends a custom registration message (i.e., a UDP datagram) to each server that includes the mapped ports and a tag denoting how the device was infected (e.g., realtek.selfrep, selfrep.router).
    • Poll for UDP packets that encode operator commands in the STUN transaction ID field.

    “From a network monitoring perspective, the activity appears as innocuous interaction with STUN servers,” Nozomi Networks said. “Given that the custom registration message is sent to every STUN server in the list, it is apparent that the operator requires visibility into at least one of the servers, in order to track new bots joining the swarm to know where to send commands to.”

    It’s worth noting these registration messages do not conform to the STUN protocol definition, causing legitimate STUN servers to drop the packet. However, one of the 13 servers (“145.249.115[.]184”) is said to have returned an all-zero transaction ID instead of echoing the transaction ID of the original Binding Request in the Binding Success Response.

    This unusual behavior, per Nozomi, suggests the STUN server is tailored to the bot’s own STUN traffic and that it’s used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field.

    The commands allow the threat actor to recursively scan and spread the scale of the botnet in a worm-like fashion, spawn/stop a TCP tunnel, launch/stop a proxy, and perform a denial-of-service (DoS) attack against a specified target for a given time duration. Some of the targets of the flooding attacks are below –

    • 112.151.157[.]222:8080 (South Korean ISP)
    • 192.170.240[.]137:53 (University of Chicago cluster)
    • 23.81.40[.]193:25565 (Minecraft)
    • 147.185.221[.]129:25565 (Minecraft)

    “The most interesting part of the C2 traffic is where the commands appeared to come from,” Nozomi Networks explained. “The packets carrying operator commands originate from 74.125.250[.]129, an IP address that stun.l.google.com resolves to.”

    Cybersecurity

    “In other words, the operator is not merely hiding commands inside a STUN-looking packet, but they are making those commands appear as if they are legitimate replies from one of the most recognizable STUN services on the internet.”

    Update

    Fortinet FortiGuard Labs, in a new report published on October 5, 2026, described the malware as exploiting unpatched vulnerabilities in internet-facing devices to establish a persistent foothold. The cybersecurity company has given it the name ClingSTUN.

    The malware has also been observed obtaining initial access by exploiting a number of other command injection flaws –

    • CVE-2019-7256 (Linear)
    • CVE-2019-17621, CVE-2022-37055, CVE-2024-23624, CVE-2024-10914, CVE-2024-10915, CVE-2024-23625 (D-Link)
    • CVE-2021-36380 (Sunhillo SureLine)
    • CVE-2022-26289, CVE-2022-35555, CVE-2024-32281, CVE-2024-32292, CVE-2024-32314, CVE-2024-35340, CVE-2024-46048 (Tenda)
    • CVE-2022-36553 (Hytec Inter HWL-2511-SS routers)
    • CVE-2023-1389 (TP-Link)
    • CVE-2023-46805, CVE-2024-21887 (Ivanti Connect Secure and Policy Secure)
    • CVE-2024-7029 (AVTECH)
    • CVE-2025-34035 (EnGenius)
    • CVE-2025-67038 (Lantronix EDS5000)
    • CVE-2026-36356 (MeiG)

    Like other botnet malware families, the attacks employ shell script downloaders to fetch malware payloads for different Linux architectures, including ARM, Intel 80386, MIPS R3000, PowerPC, and AMD X86-64.

    Once launched, Cling is equipped to terminate competitors, set up persistence mechanisms on the infected host, and facilitate remote command execution and self-propagation. To achieve self-propagation, the malware hard-codes exploits for seven vulnerabilities –

    • CVE-2014-8361 (Realtek)
    • CVE-2016-20016 (MVPower)
    • CVE-2023-26801 (LB-LINK)
    • CVE-2023-41011 (China Mobile)
    • CVE-2024-3721 (TBK)
    • CVE-2025-34037 (Linksys)
    • CVE-2026-87827 (KGUARD DVR)

    “ClingSTUN functions as a backconnect proxy backdoor, turning infected systems into remotely controlled proxy nodes,” Fortinet said. “It abuses public STUN (Session Traversal Utilities for NAT) infrastructure to discover externally mapped IP addresses and ports, maintain NAT bindings, and improve connectivity between compromised hosts and remote operators.”

    “Because many of the STUN servers it contacts are legitimate public services, the resulting traffic easily blends with normal VoIP and WebRTC communications.”

    Attempts Botnet Cling deliver exploit Jungle Realtek SDK STUNBased
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    South Korea probes bank breaches amid suspected AI-powered attacks

    New Dell System Update flaw lets hackers gain root privileges

    Denmark population registry data breach affects 8.8 million people

    The Credential Layer Is Expanding Faster Than Security Teams Can See It

    OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

    Rejetto HFS servers now actively scanned for critical RCE flaw

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    How ProPublica Reporters Became Private School Owners in 24 Hours — ProPublica

    October 6, 2026

    Europe’s Chance to Revive the Israeli-Palestinian Peace Process

    October 6, 2026

    Samoa leader apologises for Nazi salute after video from 2007 emerges

    October 6, 2026

    OpenAI will start watermarking ChatGPT’s text in the EU

    October 6, 2026
    Latest Posts

    What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience

    August 9, 2026

    Britain is paying the price for failing to invest in its young people | Richard Partington

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    How ProPublica Reporters Became Private School Owners in 24 Hours — ProPublica

    October 6, 2026

    Europe’s Chance to Revive the Israeli-Palestinian Peace Process

    October 6, 2026

    Samoa leader apologises for Nazi salute after video from 2007 emerges

    October 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.