← Blog · · df00tech

Realtek Jungle SDK Exploit Attempts Deliver 'Cling' Botnet Using STUN for C2

security-news technique

What Happened

Nozomi Networks has reported observing threat actors attempting to exploit a now-patched critical vulnerability in the Realtek Jungle software development kit (SDK) to deploy a botnet malware dubbed Cling. According to the report, Cling's notable characteristic isn't a novel propagation method, but its command-and-control (C2) design: it repurposes standard STUN (Session Traversal Utilities for NAT) protocol behavior into a functional C2 channel.

Why It Matters

The Realtek Jungle SDK is widely embedded in consumer and small-business networking and IoT devices, so vulnerabilities in it historically have had broad, multi-vendor reach across firmware from many OEMs. Even though the underlying flaw is patched, exploitation attempts in the wild indicate many deployed devices remain unpatched — a common pattern with embedded/IoT firmware where update adoption lags significantly behind disclosure. Using STUN for C2 is also operationally relevant for defenders: STUN traffic is routinely used for legitimate NAT traversal (VoIP, WebRTC, P2P apps) and is often allowed outbound with little scrutiny, making it an attractive channel for blending C2 communications into traffic that network defenses may not flag as suspicious.

What Defenders Should Watch For

  • Inventory exposure: identify IoT/embedded devices (routers, cameras, NAS, and other consumer/SMB network gear) running Realtek Jungle SDK-based firmware, and confirm they are patched against the referenced flaw.
  • Network hunting: review outbound STUN traffic (typically UDP/3478 and related ports) from IoT/embedded device segments for unusual volume, destination diversity, or connections to unexpected external hosts — legitimate STUN use is usually tied to specific VoIP/WebRTC applications, not generic IoT devices.
  • Segmentation: ensure IoT/embedded devices are isolated from sensitive network segments, limiting the blast radius if a device is compromised and recruited into a botnet.
  • Exploit-attempt signatures: monitor for known exploitation patterns/signatures targeting the Realtek Jungle SDK flaw at the network edge and in IDS/IPS telemetry, since the report describes active attempts against the (patched) vulnerability.
  • Firmware update hygiene: prioritize patching or replacing devices that cannot receive updates for this SDK-level issue.

Developing Intel

This is based on a single vendor report (Nozomi Networks) covering an emerging botnet campaign; further technical details, indicators of compromise, and the full scope of affected devices may evolve as more analysis is published. For the full details, see the original report at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.