Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Attackers exploiting Realtek Jungle SDK flaws are deploying the Cling botnet, which hides C2 in STUN traffic.
Nozomi Networks reported a spike, beginning around 5 September 2026, in attempts to exploit the patched critical Realtek Jungle SDK flaw CVE-2021-35394 (CVSS 9.8) to install the Cling botnet. The sample also embeds command-injection and remote-code-execution logic for devices from multiple vendors, including CVE-2014-8361, CVE-2016-10372, CVE-2016-20016, CVE-2023-26801, CVE-2023-41011, CVE-2024-3721, and CVE-2025-34037. Cling persists by adding itself to SysV and BusyBox init scripts or by replacing wget, then uses public STUN servers and transaction IDs for registration and commands. Those commands support worm-like scanning, TCP tunnels, proxies, and timed denial-of-service floods, including traffic aimed at a University of Chicago address and a South Korean ISP.