// 1 CRITICAL · 2 ZERO-DAY · 4 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
Threat actors are exploiting CVE-2021-35394 in the Realtek Jungle SDK to deploy the Cling botnet, which hides command-and-control traffic inside the STUN protocol. Nozomi Networks observed an exploit spike around September 5, 2026. The malware uses zeroed transaction IDs and spoofed Google STUN replies to evade detection while establishing multi-mechanism persistence and backconnect proxy capabilities across five CPU architectures.

Threat actors are exploiting CVE-2021-35394, a critical vulnerability in the Realtek Jungle SDK rated CVSS 9.8 by the National Vulnerability Database, to deploy the Cling botnet. Nozomi Networks observed a spike in exploit attempts around September 5, 2026. The malware introduces no novel propagation techniques; its distinguishing feature is the use of the STUN protocol — normally employed for NAT traversal in real-time applications — as a command-and-control channel that is practically invisible to traditional detection tools.

Key Takeaways
  • Cling uses STUN Binding Requests with a zeroed transaction ID sent to 13 hard-coded servers roughly every 5 seconds, a pattern that violates RFC 8489 but flies under conventional network signatures.
  • Operator commands are embedded in the 12-byte transaction ID field of STUN responses that appear to originate from stun.l.google.com (74.125.250.129), likely via UDP spoofing.
  • The malware establishes multi-mechanism persistence: copies itself to hidden paths, appends to boot scripts, and replaces the system wget binary with itself.
  • Payloads compiled for five architectures — ARM, Intel 80386, MIPS R3000, PowerPC, and AMD x86-64 — indicate broad targeting of multi-vendor embedded devices.

How STUN Becomes a C2 Tunnel

Session Traversal Utilities for NAT (STUN) is defined in RFC 8489 as a protocol that allows endpoints behind NAT to discover their public IP address and open ports for inbound communication. Legitimate implementations generate random 12-byte transaction IDs for each request; the STUN server responds by echoing the same identifier.

Cling inverts this logic. The malware sends Binding Requests with a systematically zeroed transaction ID to thirteen hard-coded STUN servers — mostly trusted public services — at an interval of roughly five seconds per packet. The operator-controlled server, 145.249.115.184, also responds with a zeroed transaction ID instead of the standard echo. This deviation from the RFC specification is the only detectable indicator of compromise in the traffic.

The actual commands are hidden in the transaction ID field of subsequent STUN responses. Nozomi Networks observes that these packets appear to originate from 74.125.250.129, the address of stun.l.google.com. The source notes, however, a different IP TTL compared to authentic STUN replies, an element that suggests UDP spoofing rather than compromise of Google infrastructure.

"The operator is not merely hiding commands inside a STUN-looking packet, but they are making those commands appear as if they are legitimate replies from one of the most recognizable STUN services on the internet."

Nozomi Networks

Cling's Multi-Mechanism Architecture

After gaining initial access via RCE exploit, Cling implements persistence at multiple levels. The malware copies itself to /root/.cling and /usr/local/bin/.cling, then appends references to /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot. The alternate mechanism is more insidious: it replaces the system wget binary with its own executable, moving the original to wget.r. When a process or administrator invokes wget, the malware executes its own payload first, then delegates to the original binary — a pattern that makes file-integrity-based detection particularly difficult on embedded Linux systems.

Fortinet FortiGuard Labs, in its October 5, 2026 report naming the threat ClingSTUN, confirms the malware operates as a backconnect proxy backdoor. Infected systems become remotely controllable proxy nodes with tunneling and internal pivoting capabilities. The source emphasizes that STUN traffic easily blends with legitimate VoIP and WebRTC communications, rendering generic network-based detection rules ineffective.

Multi-Vendor Targeting and Additional Vulnerabilities

Beyond CVE-2021-35394, the dossier documents seven hard-coded vulnerabilities in the malware for self-propagation, covering diverse vendors: D-Link, Tenda, Ivanti, FiberHome, LB-LINK, Linksys, Eir, MVPower, TBK. The linked CVEs in the dossier provide verifiable context for historical vulnerabilities in the same ecosystem: CVE-2014-8361 (Realtek), CVE-2016-10372 (Eir router), CVE-2016-20016 (MVPower DVR), CVE-2023-26801 (LB-LINK), and CVE-2023-41011 (FiberHome/China Mobile RCE) — the latter explicitly cited by the primary source.

The backconnect proxy capability exposes organizations to internal pivoting risks: a compromised IoT device on a perimeter network segment can become an entry point for lateral movement. Observed DoS targets include the University of Chicago cluster (192.170.240.137:53), a South Korean ISP, and Minecraft servers — a mix suggesting operators interested in both targeted disruption and commercial services.

Immediate Actions

  • Verify patched firmware for CVE-2021-35394 on all devices using Realtek Jungle SDK, prioritizing internet-exposed routers and DVRs.
  • Actively inspect embedded Linux systems for persistence via system binary replacement, with particular attention to wget integrity and init scripts.
  • Analyze outbound STUN traffic for zeroed transaction IDs in repeated Binding Requests to non-standard servers or with rigid temporal patterns of roughly 5 seconds.
  • Correlate STUN communications with response IP TTL: a discrepancy from expected values of known public servers indicates probable spoofing and C2 traffic.

Why STUN Changes the Detection Paradigm

The choice of STUN is not accidental. Unlike C2 channels based on DNS over HTTPS, TLS on non-standard ports, or proprietary protocols, STUN enjoys structural legitimacy: it is permitted by most corporate firewalls, requires no authentication, and its traffic is numerically dominant in any network hosting WebRTC or VoIP applications. The abuse of public infrastructure such as Google STUN servers adds a layer of plausibility that challenges traditional behavioral models.

The MIPS sample analyzed by GBHackers bears SHA-1 hash 3b0ac6aaabb3bf8058ca14f9c8ccc613cfa3ea71. The malware does not encrypt communications; it hides in the apparent banality of the protocol. For defenders, this means traffic profiling must descend to the implementation level — transaction ID, temporal patterns, TTL anomalies — rather than stopping at the mere presence of STUN packets.

The dossier does not quantify the infection scale, nor attribute the operation to a specific group. It also does not clarify whether the September 5, 2026 spike evolved into a sustained campaign or represents an isolated wave. What remains documented is a qualitative leap in C2 concealment: no longer masked protocols, but fully legitimate protocols used in technically anomalous ways.

Frequently Asked Questions

Why is the zeroed transaction ID relevant if the protocol requires no authentication?

RFC 8489 requires random transaction IDs to prevent collisions and replay attacks. Systematic zeroing is a non-compliant implementation pattern that uniquely identifies Cling traffic, provided network analysis descends to the individual protocol field level.

Is the wget replacement reversible without reflashing firmware?

The malware moves the original binary to wget.r. On systems with shell access and a read-write filesystem, it is technically possible to restore the original binary, provided it has not been overwritten. The dossier does not document vendor-specific remediation procedures.

Does multi-architecture targeting indicate a single operator or a shared malware family?

The dossier provides no elements to distinguish between a single operator with broad cross-compilation capability and a distributed framework. No attribution to an APT or criminal group is available.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. thehackernews.com
  2. github.com
  3. blog.netmanageit.com
  4. guardianmssp.com
  5. scworld.com
  6. gbhackers.com
  7. news.lavx.hu
  8. nvd.nist.gov