Threat Intelligence

Cling Botnet Hides Its Control Traffic in Everyday Network Chatter While Targeting Routers and DVRs

The Hacker News · 5 Oct 2026
Key Takeaway Check that routers, DVRs and other network devices are running the latest vendor firmware, replace any that no longer receive updates, and do not assume that traffic which looks like normal network activity is harmless.

Security firm Nozomi Networks has reported a spike in attempts to exploit CVE-2021-35394, a critical remote code execution flaw (CVSS score 9.8) in the Realtek Jungle software development kit. The flaw has been patched, but the activity, which began around September 5, 2026, includes a subset of attacks that deliver a botnet called Cling.

Nozomi says Cling is not notable for a new way of spreading. Its significance is that it repurposes ordinary STUN behaviour as a command-and-control channel. STUN is a standard protocol that helps devices behind a firewall or NAT set up real-time peer-to-peer communications. By abusing it and public STUN infrastructure, Cling registers infected hosts and receives operator commands, while its traffic can look like legitimate NAT-traversal activity. Nozomi says the botnet supports propagation, proxying, tunnelling and denial-of-service commands.

Analysis of a sample showed Cling carries exploit logic for command injection and remote code execution flaws in routers and DVRs from multiple vendors. It allows only one copy to run at a time and copies itself to hidden locations on the device. It is added to several startup files so it survives reboots. A second persistence method replaces the system's wget binary with the malware, after moving the original, so the malware runs whenever a legitimate process calls wget.

botnet Realtek CVE-2021-35394 IoT security routers

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.