Home / Oct 06, 2026 / Story
0
#7 The Hacker News general October 05, 2026 at 11:46 UTC

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

By [email protected] (The Hacker News)

AI Summary

A new botnet malware called Cling (also tracked as ClingSTUN) is being deployed by exploiting a critical flaw in the Realtek Jungle SDK, using legitimate STUN (Session Traversal Utilities for NAT) servers as a covert command-and-control channel to blend malicious traffic with normal WebRTC/VoIP communications. Nozomi Networks identified that Cling exploits 24 known vulnerabilities across IoT devices for self-propagation and establishes back-connect proxy nodes to obscure attacker infrastructure. The abuse of STUN protocol for C2 presents a detection challenge since STUN traffic is typically permitted through firewalls.

Relevance score: 76.0/100

# More from October 06