BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Cling botnet exploits Realtek flaw via STUN C2

  • Threat actors are exploiting a critical Realtek SDK flaw (CVE-2021-35394) to deploy a new botnet malware called Cling.
  • Cling repurposes ordinary STUN network traffic into a covert command-and-control channel, masking malicious activity.
  • The malware uses 13 STUN servers for C2, with one server appearing custom-built to deliver operator commands.
  • Cling can propagate worm-like, launch tunnels and proxies, and launch denial-of-service attacks.

Researchers at Nozomi Networks have observed threat actors actively exploiting a patched critical remote code execution flaw in the Realtek Jungle SDK, designated CVE-2021-35394, to deploy a new botnet malware called Cling since September 5, 2026. According to their report, “Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel.”

- Advertisement -

The malware copies itself to multiple locations and achieves persistence on various init systems. Consequently, an alternative mechanism involves replacing the “wget” binary on an infected system to trigger execution.

A key element of Cling is its abuse of the STUN protocol, typically used for NAT traversal. The malware sends Binding Requests every five seconds to a list of 13 STUN servers, recording the returned external ports.

It then sends a custom registration packet containing those ports, which is dropped by legitimate servers but likely read by an operator-controlled server. The operators embed commands within the STUN transaction ID field of responses, which appear to originate from a legitimate Google STUN service (74.125.250[.]129).

The botnet executes commands to propagate itself in a worm-like fashion, manage TCP tunnels, launch proxies, and perform denial-of-service attacks. Targets of these flooding attacks include a South Korean ISP, a university cluster, and Minecraft game servers.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tom Lee: 30% Q3 earnings growth, S&P 8,200+, Bitcoin $100k

Fundstrat’s Tom Lee expects the 10-year Treasury yield to fall below 5% within six...

Bitcoin Eyes Key $87,570 Level as 2026 Candle Nears Green

Bitcoin bulls briefly revisited $87,000, but the 2026 yearly open at $87,570 continues to...

Citrix NetScaler Zero-Day Exploited in Targeted Attacks

Citrix released security updates for CVE-2026-88779, a high-severity memory overflow flaw in NetScaler ADC...

US debt crisis slowly squeezes budget as interest hits $1.1T

The US debt crisis may be unfolding as a slow squeeze, with servicing costs...

Zcash’s NU7 live on testnet as November mainnet nears target

ZCash activated NU7 upgrade on testnet on October 4 at block 4,465,026.NU7 aims to...

Must Read

9 Best Trading Platforms for Crypto Beginners

Many newcomers to the crypto space are looking for platforms to buy, sell and exchange cryptocurrencies. While there are hundreds of crypto exchanges around...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading