Cling botnet leverages STUN to hide C2 activity
🔍 Nozomi Networks observed attackers exploiting a patched critical Realtek Jungle SDK RCE (CVE-2021-35394) starting around September 5, 2026, to deploy a botnet named Cling. The malware repurposes ordinary STUN traffic as a covert command-and-control channel, enabling propagation, proxying, tunneling and denial-of-service actions while resembling legitimate NAT-traversal activity. Samples embed multiple exploit payloads targeting routers and DVRs from various vendors and use persistence techniques like replacing wget and modifying init scripts.
