Cling Botnet Misuses Realtek Jungle SDK RCE via STUN-Based C2

Attackers are exploiting a critical remote code execution vulnerability in Realtek’s Jungle SDK, identified as CVE-2021-35394 (CVSS 9.8), to distribute a botnet malware named Cling. The flaw already has been patched, but exploitation attempts began escalating around September 5, 2026. Cling’s distinctive feature is its repurposing of STUN traffic—normally used for NAT traversal—as a covert command-and-control (C2) channel, evading network detection.

Multi-Vendor Reach and Persistence Techniques

An analysis revealed that Cling’s exploit logic spans vulnerabilities across multiple devices. In addition to the Realtek RCE in Jungle SDK, the malware includes exploits for:

  • An Eir D1000 router RCE (CVE-2016-10372)
  • An MVPower CCTV DVR (CVE-2016-20016)
  • LB-LINK routers (CVE-2023-26801)
  • FiberHome SR1041F and China Mobile HG6543C4 routers (CVE-2023-41011)
  • A TBK DVR RCE (CVE-2024-3721)
  • A Linksys device with RCE (CVE-2025-34037)

For persistence, Cling copies itself into locations like /root/.cling and /usr/local/bin/.cling. It then manipulates init systems (SysV and BusyBox) via files such as /etc/inittab and /etc/init.d/rcS to launch automatically on reboot. In some cases, it disguises itself by replacing the legitimate wget binary, relocating the original and ensuring malicious execution whenever wget is called.

STUN Abuse as a Hidden C2 Framework

STUN (Session Traversal Utilities for NAT) aids devices in finding their external IP addresses when behind NATs. Cling twists this protocol to create a stealthy control mechanism. It cycles every ~5 seconds through a hard-coded list of 13 STUN servers, sending binding requests with a fixed transaction ID of all zeros—violating standard procedure. On receiving responses, it extracts public IPs and port mappings. It then sends custom registration messages—tagged with infection metadata—via UDP to each server. Command retrieval is handled via STUN‐like packets encoded in the transaction ID field.

The malware even leverages traffic from a well-known STUN service—specifically an IP resolving to stun.l.google.com—for operator communications, making some malicious packets appear like legitimate protocol exchanges. This clever disguise makes detection much harder.

Command Capabilities and Attack Spectrum

Once a device is under Cling’s control, it can perform a wide array of malicious functions. These include worm-style propagation across networks, bouncing connections via TCP tunnels, acting as a proxy, and carrying out denial-of-service (DoS) attacks. Actual targets ranged from academic clusters and South Korean ISPs to public Minecraft servers.

One specific target included an IP linked to a South Korean internet service provider, another was associated with a university cluster, and others pointed to popular online game servers. Using widespread STUN infrastructure and embedding commands in transaction IDs, Cling manages to obscure both its communication and its source.

This threat also deploys a mechanism to ensure only a single instance runs: it attempts to bind to port 33957 using SO_REUSEADDR. If binding fails, the malware safely exits, preventing duplication. The dual persistence methods—through system startup scripts and substitution of the wget executable—ensure survival across reboots and common maintenance routines.

Security observers have noted that some STUN servers in the list don’t reject these malformed or non-standard messages, likely due to misconfiguration or overly permissive setups. In one case, a STUN server at “145.249.115.184” returned an all-zero transaction ID in its response—behavior matching Cling’s expectations and enabling C2 delivery.

Administrators and device operators are urged to apply the patch for CVE-2021-35394, scrutinize device behaviors for suspicious STUN traffic (especially binding requests with fixed transaction IDs), and monitor for unusual use of typical utilities like wget. Logging and network analysis focusing on STUN interactions and startup scripts will likely uncover infection.

The emergence of Cling highlights a growing trend: malware abusing infrastructure and protocols designed for lawful networking to hide malicious traffic. Using STUN—a staple in real-time communication and VPN setups—as a C2 channel is especially concerning. As more IoT and networking devices employ STUN, miscreants are finding fertile ground to mask botnet activity; the breach of trust here could reduce reliance on these protocols if defenders can’t distinguish good from bad. The adoption and improvement of detection capabilities around STUN behavior anomalies will likely determine how swiftly similar threats can be neutralized in the future.