CVE-2021-35394 — a critical remote code execution flaw in the Realtek Jungle SDK — was the focal point of a spike in exploit attempts beginning around September 5, 2026, and some of that activity delivered a botnet named Cling, Nozomi Networks reported.
How Cling turns STUN into a command-and-control channel
Nozomi Networks described Cling as "notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel." The malware abuses the Session Traversal Utilities for NAT (STUN) protocol — normally used to help devices behind NATs or firewalls establish peer-to-peer real‑time communications — to register infected hosts, receive operator commands, and camouflage malicious traffic.
The sample follows a clear, four-step process for C2 communications:
- It sends a STUN Binding Request to a hard-coded list of 13 STUN servers roughly every five seconds, but sets the transaction ID to all zeros instead of a random value.
- It records the externally observed ports returned by Binding Success Response messages, which include the public IP and associated port numbers.
- It sends a custom registration UDP datagram to each server that includes the mapped ports and a tag showing how the device was infected (for example, "realtek.selfrep" or "selfrep.router").
- It polls for UDP packets that encode operator commands in the STUN transaction ID field.
Nozomi emphasized that "from a network monitoring perspective, the activity appears as innocuous interaction with STUN servers," and that the operator requires visibility into at least one of the listed STUN servers to track new bots and deliver commands.
Exploit surge centered on a now-patched Realtek Jungle SDK flaw
The operational-technology security firm observed a spike in attempts to exploit CVE-2021-35394, a critical RCE in the Realtek Jungle SDK, with some exploitation attempts delivering the Cling payload. The report characterizes this activity as beginning around September 5, 2026.
Cling’s sample embeds exploit logic for multiple previously disclosed router and DVR vulnerabilities across several vendors, indicating a broad toolset for initial compromise. The vendor- and CVE-level list in the sample includes:
- Realtek SDK RCE (CVE-2014-8361)
- Eir D1000 router RCE (CVE-2016-10372)
- MVPower CCTV DVR RCE (CVE-2016-20016)
- LB-LINK routers RCE (CVE-2023-26801)
- FiberHome SR1041F / China Mobile HG6543C4 RCE (CVE-2023-41011)
- TBK DVR RCE (CVE-2024-3721)
- Linksys RCE (CVE-2025-34037)

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coveragePersistence, single‑instance checks and stealthy binaries
Nozomi’s analysis details multiple persistence and stealth mechanisms. The malware enforces a single-instance check by binding a socket with SO_REUSEADDR to port 33957 and exiting cleanly if that bind fails. The sample copies itself to /root/.cling and /usr/local/bin/.cling and appends both executables to init scripts and tables — /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot — to achieve persistence on SysV and BusyBox init systems.
An alternative persistence method looks for a system’s wget binary, moves the original to another location, and replaces it with the malware so that legitimate invocations of "wget" execute the payload.
Command capabilities, observed DoS targets, and the illusion of legitimacy
Operator-issued commands delivered via STUN transaction IDs give the botnet several capabilities: recursively scanning and spreading in a worm-like fashion, spawning or stopping TCP tunnels, enabling or disabling proxy functions, and launching denial-of-service attacks for specified durations. Nozomi noted the botnet supports "propagation, proxying, tunneling and denial-of-service commands."
The report lists examples of flood targets observed in activity associated with the botnet, reproduced here verbatim:
- 112.151.157[.]222:8080 (South Korean ISP)
- 192.170.240[.]137:53 (University of Chicago cluster)
- 23.81.40[.]193:25565 (Minecraft)
- 147.185.221[.]129:25565 (Minecraft)
Perhaps most striking is how the operator makes command traffic appear to originate from a well-known STUN endpoint. Nozomi observed that "the packets carrying operator commands originate from 74.125.250[.]129, an IP address that stun.l.google.com resolves to." In other words, the operator both hides commands inside STUN-like packets and makes them appear as if they are legitimate replies from a widely recognized STUN service.
What this means for technologists, device vendors, and network operators
- Technologists and security teams: Watch for STUN Binding Requests with an all-zero transaction ID, repeated connections to a fixed list of STUN servers, registration UDP datagrams that deviate from the STUN protocol, evidence of binding to local port 33957, unexpected copies at /root/.cling or /usr/local/bin/.cling, modifications to /etc/inittab or init scripts, and a replaced wget binary.
- Device vendors and maintainers: The activity centered on a now-patched Realtek Jungle SDK flaw; vendors whose products use affected SDK components should ensure updates are applied and validate that older vulnerability remediation is complete across firmware inventories.
- Network operators and ISPs: Because the botnet uses public STUN infrastructure and can make commands appear to come from a major STUN service, monitoring for unusual STUN traffic patterns — including repeated Binding Requests with nonstandard transaction IDs and nonconforming registration packets — will be important to detect abuse that otherwise looks legitimate.
Cling’s novelty is not a new exploit but a repurposing of an established protocol to mask control and coordination. As Nozomi observed, the operator is not merely hiding commands inside STUN-like packets but is "making those commands appear as if they are legitimate replies from one of the most recognizable STUN services on the internet." That observation underscores a narrower, practical question left on the table: which of the listed STUN endpoints is being used as a bespoke rendezvous for commands, and how many infected devices already rely on that covert channel?
Original reporting: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html




