VMTech
Discuss a project →

Cling botnet targets Realtek Jungle SDK through STUN-based control

Cling botnet targets Realtek Jungle SDK through STUN-based control

Nozomi Networks has observed a spike in attempts to exploit CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle software development kit. Activity began around September 5, 2026, and a subset of the attacks delivered the Cling botnet. The flaw carries a CVSS score of 9.8 and has been patched.

Cling stands out for using Session Traversal Utilities for NAT, or STUN, as a command-and-control channel. STUN is commonly used to help devices behind NATs or firewalls establish peer-to-peer real-time communications. That familiar traffic can make the botnet's network activity appear less conspicuous while it supports propagation, proxying, tunnelling and denial-of-service commands.

Malware carries exploits for routers and DVRs

Nozomi's analysis found that the Cling sample embeds exploit logic for multiple command-injection and remote-code-execution weaknesses affecting routers and DVRs. These include Realtek SDK RCE CVE-2014-8361, Eir D1000 CVE-2016-10372, MVPower CCTV DVR CVE-2016-20016, LB-LINK CVE-2023-26801, FiberHome SR1041F and China Mobile HG6543C4 CVE-2023-41011, TBK DVR CVE-2024-3721, and Linksys CVE-2025-34037.

The malware limits itself to one running instance by binding a socket, with SO_REUSEADDR, to port 33957 and exiting if that operation fails. It copies itself to /root/.cling and /usr/local/bin/.cling, then appends both executables to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot for persistence on SysV and BusyBox init systems.

An alternative persistence method searches for wget, moves the legitimate binary elsewhere and replaces it with the malware. This means a legitimate process that invokes the wget command can execute Cling instead.

STUN requests conceal the command channel

For command-and-control communications, Cling sends STUN Binding Requests to a hard-coded list of 13 STUN servers roughly every five seconds. Its transaction ID is all zeros rather than the random value required by the STUN specification. The malware records the externally observed ports returned in Binding Success Response messages.

It then sends a custom UDP registration datagram to each listed server. The message includes the mapped ports and a tag indicating the infection route, such as realtek.selfrep or selfrep.router. Finally, it polls for UDP packets carrying operator commands encoded in the STUN transaction ID field.

The registration messages do not conform to the STUN protocol and legitimate servers should drop them. However, Nozomi identified one server, 145.249.115[.]184, that returned an all-zero transaction ID rather than echoing the request identifier. The company said this behaviour suggests infrastructure tailored to the bot's STUN traffic and used to deliver commands.

Operational commands and defensive priorities

Cling's commands can recursively scan for devices and spread in a worm-like manner, start or stop a TCP tunnel, launch or stop a proxy, and conduct a denial-of-service attack against a specified target for a defined duration. Nozomi also found command packets that appeared to originate from 74.125.250[.]129, an address to which stun.l.google.com resolves.

For businesses operating exposed routers, DVRs or other Realtek-based equipment, the practical implication is to apply the available patch for CVE-2021-35394, review device persistence changes, and scrutinise STUN traffic for all-zero transaction IDs, repeated five-second requests and non-standard UDP registration messages.

#cybersecurity#botnet#iotsecurity#networksecurity
Open analytics
On the site 0 views
min read 4 05.10.2026
Instagram

Cling botnet targets Realtek Jungle SDK through STUN-based control

Open the post on Instagram ↗