importantSYS.SOURCE: The Hacker News• 2026-10-05T17:16:25+05:30
Exploitation of Realtek Jungle SDK Vulnerability Leads to Cling Botnet Deployment via STUN C2
Threat actors are exploiting a patched vulnerability in the Realtek Jungle SDK to deploy the Cling botnet, which uses STUN protocol for covert command-and-control communications. The malware leverages multiple RCE vulnerabilities and disguises malicious traffic as legitimate NAT-traversal activity to evade detection.
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling.
"Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report
*** END OF TRANSMISSION ***