{"id":244938,"date":"2026-10-06T01:32:34","date_gmt":"2026-10-06T06:32:34","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/10\/realtek-jungle-sdk-exploit-attempts-deliver-cling-botnet-with-stun-based-c2"},"modified":"2026-10-06T01:32:34","modified_gmt":"2026-10-06T06:32:34","slug":"realtek-jungle-sdk-exploit-attempts-deliver-cling-botnet-with-stun-based-c2","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/10\/realtek-jungle-sdk-exploit-attempts-deliver-cling-botnet-with-stun-based-c2","title":{"rendered":"Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/realtek-jungle-sdk-exploit-attempts-deliver-cling-botnet-with-stun-based-c2.webp\"><\/a><\/p>\n<p>Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called <strong>Cling<\/strong>.<\/p>\n<p>\u201cCling is notable not because it introduces a new propagation technique, but because it repurposes ordinary <a href=\"https:\/\/thehackernews.com\/2023\/07\/vishing-goes-high-tech-new-letscall.html\" target=\"_blank\">STUN behavior<\/a> into a practical command-and-control channel,\u201d Nozomi Networks <a href=\"https:\/\/www.nozominetworks.com\/blog\/a-stunning-disguise-cling-malware-masquerades-as-google-\" target=\"_blank\">said<\/a> in a report published last week. \u201cThe result is a botnet whose traffic can resemble legitimate NAT-traversal activity while still supporting propagation, proxying, tunneling and denial-of-service commands.\u201d<\/p>\n<p>The operational technology (OT) security company said it observed a spike in attempts to exploit <a href=\"https:\/\/thehackernews.com\/2023\/01\/realtek-vulnerability-under-attack-134.html\" target=\"_blank\">CVE-2021\u201335394<\/a> (CVSS score: 9.8), a critical <a href=\"https:\/\/www.sentinelone.com\/vulnerability-database\/cve-2021-35394\/\" target=\"_blank\">remote code execution (RCE) flaw<\/a> in Realtek Jungle SDK starting around September 5, 2026, with a subset of the activity delivering Cling.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. \u201cCling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel,\u201d Nozomi Networks said in [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[],"class_list":["post-244938","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244938","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=244938"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244938\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=244938"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=244938"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=244938"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}