Cling Botnet Exploits Realtek SDK Flaw and Hides Commands Inside STUN Traffic
Threat actors are exploiting a patched critical vulnerability in the Realtek Jungle software development kit (SDK) to spread a botnet malware called Cling. What makes this botnet stand out is how it disguises its command-and-control (C2) communication as ordinary STUN traffic, making malicious activity look like legitimate network behavior.
Realtek Flaw Behind the Spike
Operational technology (OT) security company Nozomi Networks reported a surge in exploitation attempts targeting CVE-2021-35394 starting around September 5, 2026. The flaw is a critical remote code execution (RCE) bug in Realtek Jungle SDK with a CVSS score of 9.8. A portion of this activity was found delivering Cling.
According to Nozomi, Cling does not bring a new spreading technique. Its real innovation is turning normal STUN behavior into a working C2 channel, allowing it to support propagation, proxying, tunneling, and denial-of-service (DoS) attacks while blending in with legitimate NAT traversal traffic.
Built-In Exploits for Routers and DVRs
The analyzed sample contains exploit code for multiple command injection and RCE flaws in routers and DVRs:
- CVE-2014-8361 (Realtek SDK RCE)
- CVE-2016-10372 (Eir D1000 router RCE)
- CVE-2016-20016 (MVPower CCTV DVR RCE)
- CVE-2023-26801 (LB-LINK routers RCE)
- CVE-2023-41011 (FiberHome SR1041F router and China Mobile HG6543C4 RCE)
- CVE-2024-3721 (TBK DVR RCE)
- CVE-2025-34037 (Linksys RCE)
How Cling Stays on Infected Devices
To make sure only one copy runs at a time, Cling tries to bind a socket to port 33957 and exits if that fails. It then copies itself to /root/.cling and /usr/local/bin/.cling and adds both paths to /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot, ensuring persistence on SysV and BusyBox based systems.
As a backup method, the malware locates the system's wget binary, moves the original elsewhere, and replaces it with itself. Any legitimate process that later calls wget ends up launching the malware.
What Is STUN
STUN (Session Traversal Utilities for NAT) is a standard protocol that helps devices behind a NAT or firewall set up peer-to-peer real-time connections, commonly used in VoIP and WebRTC.
How Cling Abuses STUN for C2
Cling follows a four-step process to communicate with its operators:
- It sends STUN Binding Requests to a hard-coded list of 13 STUN servers about every five seconds, using an all-zero transaction ID instead of the random value the protocol expects.
- It records the public IP address and external ports returned in the servers' Binding Success Responses.
- It sends a custom UDP registration message to every server, containing the mapped ports and a tag showing how the device was infected, such as realtek.selfrep or selfrep.router.
- It listens for UDP packets that carry operator commands encoded in the STUN transaction ID field.
To network monitoring tools, all of this looks like harmless STUN activity. Nozomi notes that since the registration message goes to every server on the list, the operator likely controls or monitors at least one of them to track new bots.
A Rogue STUN Server
Legitimate STUN servers drop the registration messages because they do not follow the protocol. However, one server in the list, 145.249.115[.]184, replied with an all-zero transaction ID rather than echoing the original request's ID. Nozomi believes this server is custom-built for the botnet and used to push commands to infected devices.
Even more notably, packets carrying operator commands were seen coming from 74.125.250[.]129, an IP address that stun.l.google.com resolves to. This makes the commands appear to be genuine replies from one of the internet's most widely used STUN services.
Botnet Capabilities
Operator commands allow Cling to:
- Scan and spread to new devices in a worm-like manner
- Start and stop TCP tunnels
- Launch and stop proxy services
- Run DoS attacks against a chosen target for a set duration
Observed DoS targets include:
- 112.151.157[.]222:8080 (South Korean ISP)
- 192.170.240[.]137:53 (University of Chicago cluster)
- 23.81.40[.]193:25565 (Minecraft server)
- 147.185.221[.]129:25565 (Minecraft server)
Fortinet Tracks It as ClingSTUN
Fortinet FortiGuard Labs published its own analysis on October 5, 2026, naming the malware ClingSTUN. Fortinet describes it as a backconnect proxy backdoor that turns compromised systems into remotely controlled proxy nodes. Because it talks to legitimate public STUN servers, its traffic easily blends in with normal VoIP and WebRTC communication.
Fortinet observed the malware gaining initial access through a much wider range of command injection flaws:
- CVE-2019-7256 (Linear)
- CVE-2019-17621, CVE-2022-37055, CVE-2024-23624, CVE-2024-23625, CVE-2024-10914, CVE-2024-10915 (D-Link)
- CVE-2021-36380 (Sunhillo SureLine)
- CVE-2022-26289, CVE-2022-35555, CVE-2024-32281, CVE-2024-32292, CVE-2024-32314, CVE-2024-35340, CVE-2024-46048 (Tenda)
- CVE-2022-36553 (Hytec Inter HWL-2511-SS routers)
- CVE-2023-1389 (TP-Link)
- CVE-2023-46805, CVE-2024-21887 (Ivanti Connect Secure and Policy Secure)
- CVE-2024-7029 (AVTECH)
- CVE-2025-34035 (EnGenius)
- CVE-2025-67038 (Lantronix EDS5000)
- CVE-2026-36356 (MeiG)
The attacks use shell script downloaders to fetch payloads built for multiple Linux architectures, including ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64. Once running, the malware kills competing malware, sets up persistence, enables remote command execution, and spreads itself using seven hard-coded exploits:
- CVE-2014-8361 (Realtek)
- CVE-2016-20016 (MVPower)
- CVE-2023-26801 (LB-LINK)
- CVE-2023-41011 (China Mobile)
- CVE-2024-3721 (TBK)
- CVE-2025-34037 (Linksys)
- CVE-2026-87827 (KGUARD DVR)
Key Takeaway
Cling shows how attackers can hide C2 traffic inside trusted protocols and even make it appear to come from well-known services like Google's STUN servers. Organizations should patch internet-facing routers, DVRs, and IoT devices, retire unsupported hardware, and watch for unusual STUN traffic patterns, such as all-zero transaction IDs or non-standard UDP messages sent to STUN servers.