THREAT researchers have observed renewed attempts to exploit a now-patched critical vulnerability in Realtek Jungle SDK to deploy a botnet known as Cling. Nozomi Networks notes that Cling repurposes STUN (Session Traversal Utilities for NAT) traffic as a practical command-and-control (C2) channel, producing network activity that can resemble legitimate NAT-traversal traffic while still enabling botnet propagation, proxying, tunnelling and distributed denial-of-service commands. The initial trigger is linked to CVE-2021-35394 (RCE, CVSS 9.8) in Realtek Jungle SDK, with activity observed from around 5 September 2026.
Malware analysis shows the Cling sample embeds exploit logic for multiple, older remote code execution flaws affecting routers and DVRs from various vendors, including Realtek SDK RCE (CVE-2014-8361), Eir D1000 router (CVE-2016-10372), MVPower CCTV DVR (CVE-2016-20016), LB-LINK routers (CVE-2023-26801), FiberHome SR1041F / China Mobile HG6543C4 (CVE-2023-41011), TBK DVR (CVE-2024-3721) and Linksys devices (CVE-2025-34037).
The sample also implements persistence by duplicating itself to /root/.cling and /usr/local/bin/.cling and appending itself to several init scripts on SysV and BusyBox systems; alternative persistence involves replacing wget to hijack legitimate downloads. Cling communicates with a hard-coded list of 13 STUN servers, sending repeated Binding Requests with a zeroed transaction ID, collecting externally observed ports, and then transmitting a custom UDP registration message that embeds infection metadata.
Some C2 traffic appears to originate from a Google STUN address, reflecting an operator attempting to blend botnet commands with seemingly legitimate responses. In practical terms, the operator can worm the network, spawn or halt TCP tunnels and proxies, and trigger DoS floods against listed targets.