A new cyberattack campaign is underway, with security researchers warning of an active exploitation of a critical vulnerability in the Realtek Jungle SDK. Attackers are exploiting this weakness to gain access to vulnerable devices and install Cling, a botnet with a highly unusual communication architecture.

What makes the campaign notable is not only the use of known attack techniques, but mainly the way in which Cling attempts to hide its communication behind legitimate network traffic.
Realtek Jungle SDK: Critical vulnerability CVE-2021-35394 targeted
According to analysis by Nozomi Networks, attempts to exploit CVE-2021-35394 intensified around September 5, 2026. This vulnerability has a CVSS score of 9.8 and concerns a remote code execution in the Realtek Jungle SDK.
The SDK has been used in products and devices from many manufacturers, which significantly expands the potential attack surface. A successful exploit could give an attacker the ability to execute commands on the device without requiring physical access.
See also: Sality Botnet: Dismantling the infamous P2P botnet
The release of a patch does not mean, however, that devices are automatically protected. On older routers, DVRs, and other embedded devices, firmware updates are often delayed or never installed.
Cling targets routers and DVRs
Cling's analysis shows that the malware is not solely based on CVE-2021-35394. It includes built-in exploits for a number of known vulnerabilities affecting routers and video capture devices.
Among others, the malware has code for CVE-2014-8361, CVE-2016-10372, CVE-2016-20016, CVE-2023-26801, CVE-2023-41011, CVE-2024-3721 and CVE-2025-34037.
This approach suggests that the target is not a specific device or manufacturer. Instead, the perpetrators appear to have created malware that can exploit different device ecosystems and quickly expand the network of infected hosts.

Persistence mechanisms to stay active
Once installed, Cling implements techniques that aim to maintain its presence even after the device is rebooted.
The malware copies itself to the /root/.cling and /usr/local/bin/.cling, and modifies startup files such as /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot. This allows it to automatically reboot on systems using SysV init or BusyBox.
Even more aggressive is an alternative mechanism persistence. Cling looks for the legitimate wget and, after moving the original file, replaces it with its own binary. Thus, any legitimate call to the wget command can also trigger the malware.
The unusual abuse of STUN
The most interesting feature of Cling is the way it communicates with the command and control infrastructure.
The malware abuses the STUN, which is normally used to help devices behind NAT or firewalls perform peer-to-peer communications.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Masjesu Botnet: DDoS-for-Hire Service Targets IoT Devices
Cling sends STUN Binding Requests to a predefined list of 13 serversapproximately every five seconds. It then records information about the public IP and external ports of the infected device.
This is followed by sending specially crafted UDP packets, which essentially function as bot registration messages on the attacker's network. The malware then waits for special UDP packets, in which the operator's commands are hidden within the STUN transaction ID field.
From scanning to DoS attacks
Through this infrastructure, the operator can issue commands that significantly expand the botnet's capabilities.
Cling can recursively scan for new vulnerable devices, allowing the network to expand with worm-like behavior. It can also create and terminate TCP tunnels, activate proxy servers, and launch DoS attacks against selected targets.

The researchers identified, among other things, infrastructure related to internet services in South Korea, university servers and Minecraft servers.
Google STUN adds another layer of concealment
Of particular interest is the origin of some packets containing C2 commands. According to Nozomi Networks, the traffic appeared to originate from the address 74.125.250[.]129, which maps to stun.l.google.com.
See also: Evooo1Bot: New Linux Botnet Turns Devices into SOCKS5 Proxies
This means that attackers attempt to make malicious communication look like legitimate activity to a widely recognized service. For network monitoring systems , a simple STUN communication can easily be lost in the large volume of legitimate traffic.
The Cling case thus highlights a broader trend in cybersecurity: attackers don't always need to create new protocols or overtly suspicious infrastructure. They can leverage perfectly legitimate services and protocols as cover.
For administrators of routers, DVRs and IoT devices, promptly installing available firmware and security updates, disabling non-essential services and limiting device exposure to the Internet are now critical defense measures against botnets of this type.
