Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

A sophisticated botnet has been discovered using a previously unknown vulnerability in the Realtek Jungle SDK, a widely used software development kit for embedded systems. The “Cling” botnet is spreading rapidly, affecting devices with exposed STUN (Session Traversal Utilities for NAT) servers.

The Cling botnet attempts to exploit a zero-day vulnerability in the Realtek Jungle SDK, which allows attackers to gain control over affected devices and use them as stepping stones for further attacks. The vulnerability affects various embedded systems, including routers, modems, and set-top boxes, making it a significant threat to internet infrastructure.

The botnet’s command-and-control (C2) server is located at a STUN server, which normally helps devices communicate over the internet by traversing network address translation (NAT) firewalls. Attackers have leveraged this service to establish a backdoor into affected devices, making it difficult for security teams to detect and mitigate the attack.

The Cling botnet’s presence has been spotted in several countries worldwide, including Europe, Asia, and North America. Affected devices show symptoms such as sudden performance degradation, abnormal network activity, and unexpected reboots. Users are advised to check their devices’ firmware versions and update them if necessary.

A deep dive into the Cling botnet’s attack chain reveals a complex process involving privilege escalation and cross-domain attacks. Attackers first identify exposed STUN servers through online directories, then inject malware into vulnerable devices using the zero-day vulnerability. The malware establishes a foothold on the device, allowing attackers to move laterally within networks.

The widespread use of Realtek Jungle SDK in various industries makes this botnet particularly concerning. If left unchecked, Cling could potentially lead to cascading attacks on internet infrastructure, compromising user data and disrupting critical services.

To protect against the Cling botnet, users are advised to regularly update their devices’ firmware, secure STUN servers, and implement robust network segmentation strategies. Additionally, network administrators should monitor for suspicious activity and maintain up-to-date threat intelligence feeds to stay ahead of emerging threats.


Source: The Hacker News — 2026-10-05