Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
By [email protected] (The Hacker News)
AI Summary
A new botnet malware called Cling (also tracked as ClingSTUN) is being deployed by exploiting a critical flaw in the Realtek Jungle SDK, using legitimate STUN (Session Traversal Utilities for NAT) servers as a covert command-and-control channel to blend malicious traffic with normal WebRTC/VoIP communications. Nozomi Networks identified that Cling exploits 24 known vulnerabilities across IoT devices for self-propagation and establishes back-connect proxy nodes to obscure attacker infrastructure. The abuse of STUN protocol for C2 presents a detection challenge since STUN traffic is typically permitted through firewalls.
Relevance score: 76.0/100
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →