- Threat actors are exploiting a critical Realtek SDK flaw (CVE-2021-35394) to deploy a new botnet malware called Cling.
- Cling repurposes ordinary STUN network traffic into a covert command-and-control channel, masking malicious activity.
- The malware uses 13 STUN servers for C2, with one server appearing custom-built to deliver operator commands.
- Cling can propagate worm-like, launch tunnels and proxies, and launch denial-of-service attacks.
Researchers at Nozomi Networks have observed threat actors actively exploiting a patched critical remote code execution flaw in the Realtek Jungle SDK, designated CVE-2021-35394, to deploy a new botnet malware called Cling since September 5, 2026. According to their report, “Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel.”
The malware copies itself to multiple locations and achieves persistence on various init systems. Consequently, an alternative mechanism involves replacing the “wget” binary on an infected system to trigger execution.
A key element of Cling is its abuse of the STUN protocol, typically used for NAT traversal. The malware sends Binding Requests every five seconds to a list of 13 STUN servers, recording the returned external ports.
It then sends a custom registration packet containing those ports, which is dropped by legitimate servers but likely read by an operator-controlled server. The operators embed commands within the STUN transaction ID field of responses, which appear to originate from a legitimate Google STUN service (74.125.250[.]129).
The botnet executes commands to propagate itself in a worm-like fashion, manage TCP tunnels, launch proxies, and perform denial-of-service attacks. Targets of these flooding attacks include a South Korean ISP, a university cluster, and Minecraft game servers.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
