Threat actors have begun exploiting a patched critical security flaw in the Realtek Jungle software development kit to deploy a botnet called Cling, according to a report published by Nozomi Networks last week. The operational technology security company detected a surge in exploitation attempts targeting CVE-2021-35394, a critical remote code execution vulnerability with a CVSS score of 9.8, starting around September 5, 2026. The malware stands out for repurposing standard STUN protocol behavior into a command-and-control mechanism that can blend with legitimate network traffic.

The Cling malware embeds exploit code for at least seven vulnerabilities affecting routers and DVRs from multiple manufacturers, including Realtek SDK (CVE-2014-8361), Eir D1000 routers (CVE-2016-10372), MVPower CCTV DVR (CVE-2016-20016), LB-LINK routers (CVE-2023-26801), FiberHome and China Mobile devices (CVE-2023-41011), TBK DVR (CVE-2024-3721), and Linksys hardware (CVE-2025-34037). Once executed, the malware copies itself to /root/.cling and /usr/local/bin/.cling, then appends both executables to initialization files like /etc/inittab and /etc/init.d/rcS to maintain persistence across reboots. An alternative persistence method involves replacing the wget binary with the malware while moving the original executable to another location, causing the malware to run whenever a legitimate process calls the wget command. Fortinet FortiGuard Labs, in a report published October 5, 2026, identified additional initial access vectors including command injection flaws in devices from Linear, D-Link, Sunhillo, Tenda, Hytec, TP-Link, Ivanti, AVTECH, EnGenius, Lantronix, and MeiG—bringing the total exploitation arsenal to more than two dozen vulnerabilities.

The report explains that Cling is "notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel." The malware sends STUN Binding Requests to a hardcoded list of 13 STUN servers approximately every five seconds, setting the transaction ID to all zeros rather than a random value as the protocol specification requires. It then records the externally visible ports returned by those servers and transmits a custom registration message to each server containing the mapped ports and a tag indicating the infection method, such as "realtek.selfrep" or "selfrep.router." According to Nozomi Networks, "from a network monitoring perspective, the activity appears as innocuous interaction with STUN servers," making malicious behavior difficult to distinguish from legitimate NAT-traversal communications used in VoIP and WebRTC applications.

The command-and-control architecture relies on operator commands embedded within the STUN transaction ID field of UDP packets. One of the 13 STUN servers—located at IP address 145.249.115[.]184—returned an all-zero transaction ID instead of echoing the original Binding Request's transaction ID in the Binding Success Response, behavior Nozomi describes as "unusual" and suggesting the server is "tailored to the bot's own STUN traffic." More striking still, the packets carrying operator commands appear to originate from 74.125.250[.]129, an IP address that stun.l.google.com resolves to, meaning the operator is making commands look like legitimate replies from Google's widely used STUN service. The commands enable the botnet to recursively scan and propagate in worm-like fashion, spawn or terminate TCP tunnels and proxy connections, and launch denial-of-service attacks against specified targets for set durations. Observed flooding targets included a South Korean ISP, a University of Chicago cluster, and two Minecraft servers.

The report notes that Cling functions as a backconnect proxy backdoor, transforming infected systems into remotely controlled proxy nodes while its traffic blends with normal internet communications. The malware's reliance on public STUN infrastructure—much of it operated by legitimate services—allows it to maintain NAT bindings and improve connectivity between compromised hosts and remote operators without raising immediate red flags. Fortinet observes that because many contacted STUN servers are legitimate public services, the resulting traffic easily blends with standard VoIP and WebRTC communications. Organizations running vulnerable routers, DVRs, and other internet-facing devices remain at risk unless patches addressing the exploited vulnerabilities have been applied, with the malware's ability to mimic benign network behavior complicating detection efforts. The convergence of decades-old unpatched vulnerabilities with sophisticated evasion techniques transforms routine network devices into stealthy proxy infrastructure that defenders may struggle to identify using traditional monitoring tools.