Cybersecurity experts have identified attempts to exploit a critical vulnerability in the Realtek Jungle SDK to deploy a botnet known as Cling. This botnet utilizes the STUN protocol, typically used for NAT traversal, to create a command-and-control channel that mimics legitimate network traffic. This approach makes Cling's operations difficult to detect through standard network monitoring tools. The vulnerability being targeted is CVE-2021-35394, a remote code execution flaw with a severity score of 9.8, which has already been patched. Despite the patch, the exploitation attempts have increased since early September, targeting devices such as routers and DVRs.

Cling's persistence mechanisms are notable. It achieves persistence by copying itself to specific directories and altering system initialization files. An alternative method involves replacing the wget binary on infected systems while moving the original to another location, ensuring execution when the wget command is used. The malware's command-and-control communications involve a four-step process that abuses the STUN protocol to send operator commands, thereby registering infected hosts and disguising malicious activity.

Interestingly, Cling's C2 traffic originates from an IP address linked to Google's STUN services, further obscuring its presence. Fortinet's report highlights Cling's ability to exploit unpatched vulnerabilities in internet-facing devices, establishing persistent footholds through various architectures. The botnet also hard-codes exploits for multiple vulnerabilities, facilitating remote execution and self-propagation, and operates as a backconnect proxy backdoor. This exploitation of public STUN infrastructure allows Cling to blend its traffic with normal communications, making detection more challenging.