AI Weekly Malaysia

Back to items Summaries

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

ID
31871
Status
summarized
Published
05 Oct 2026, 7:46 PM
Fetched
05 Oct 2026, 9:21 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
05 Oct 2026, 9:40 PM
Tags
Audience
developers

What happened

Nozomi Networks reports a spike, starting around September 5, 2026, in exploitation attempts against CVE-2021-35394 (CVSS 9.8), a critical RCE in the Realtek Jungle SDK, with some attempts delivering a botnet called Cling. The Cling sample bundles exploit logic for at least eight router/DVR flaws (including CVE-2014-8361, CVE-2016-10372, CVE-2016-20016, CVE-2023-26801, CVE-2023-41011, CVE-2024-3721 and CVE-2025-34037), persists via /root/.cling and /usr/local/bin/.cling appended to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot, and uses a single-instance lock on port 33957 with SO_REUSEADDR. Its distinguishing trick is repurposing ordinary STUN traffic and public STUN infrastructure as command-and-control, so malicious traffic resembles legitimate NAT-traversal activity.

Why it matters

For most builders in this community — people shipping web, SaaS, or AI-agent products — this is close to a no-op: the affected surface is Realtek SDK-based routers and DVRs, not application stacks, and the flaw is already patched. The one concrete takeaway is for anyone writing network detection rules or building WebRTC/STUN-dependent apps: Cling shows public STUN servers can carry C2, so blanket-allowing STUN outbound as 'just NAT traversal' is no longer a safe assumption, and detection should look at destination and volume patterns rather than the protocol alone. If you don't run embedded networking gear or monitor networks, there is no action here.

Discussion angle

STUN as a covert channel: if you were building detection, what signal would actually separate Cling's C2 from legitimate NAT traversal — destination reputation, payload shape, or session volume — and does that change how you'd allowlist UDP outbound in your own infra?

Top