Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
- ID
- 31871
- Status
- summarized
- Published
- 05 Oct 2026, 7:46 PM
- Fetched
- 05 Oct 2026, 9:21 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 05 Oct 2026, 9:40 PM
- Tags
- Audience
- developers
What happened
Nozomi Networks reports a spike, starting around September 5, 2026, in exploitation attempts against CVE-2021-35394 (CVSS 9.8), a critical RCE in the Realtek Jungle SDK, with some attempts delivering a botnet called Cling. The Cling sample bundles exploit logic for at least eight router/DVR flaws (including CVE-2014-8361, CVE-2016-10372, CVE-2016-20016, CVE-2023-26801, CVE-2023-41011, CVE-2024-3721 and CVE-2025-34037), persists via /root/.cling and /usr/local/bin/.cling appended to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot, and uses a single-instance lock on port 33957 with SO_REUSEADDR. Its distinguishing trick is repurposing ordinary STUN traffic and public STUN infrastructure as command-and-control, so malicious traffic resembles legitimate NAT-traversal activity.
Why it matters
For most builders in this community — people shipping web, SaaS, or AI-agent products — this is close to a no-op: the affected surface is Realtek SDK-based routers and DVRs, not application stacks, and the flaw is already patched. The one concrete takeaway is for anyone writing network detection rules or building WebRTC/STUN-dependent apps: Cling shows public STUN servers can carry C2, so blanket-allowing STUN outbound as 'just NAT traversal' is no longer a safe assumption, and detection should look at destination and volume patterns rather than the protocol alone. If you don't run embedded networking gear or monitor networks, there is no action here.
Discussion angle
STUN as a covert channel: if you were building detection, what signal would actually separate Cling's C2 from legitimate NAT traversal — destination reputation, payload shape, or session volume — and does that change how you'd allowlist UDP outbound in your own infra?