Cling Botnet Hides Its Control Traffic in Everyday Network Chatter While Targeting Routers and DVRs
Security firm Nozomi Networks has reported a spike in attempts to exploit CVE-2021-35394, a critical remote code execution flaw (CVSS score 9.8) in the Realtek Jungle software development kit. The flaw has been patched, but the activity, which began around September 5, 2026, includes a subset of attacks that deliver a botnet called Cling.
Nozomi says Cling is not notable for a new way of spreading. Its significance is that it repurposes ordinary STUN behaviour as a command-and-control channel. STUN is a standard protocol that helps devices behind a firewall or NAT set up real-time peer-to-peer communications. By abusing it and public STUN infrastructure, Cling registers infected hosts and receives operator commands, while its traffic can look like legitimate NAT-traversal activity. Nozomi says the botnet supports propagation, proxying, tunnelling and denial-of-service commands.
Analysis of a sample showed Cling carries exploit logic for command injection and remote code execution flaws in routers and DVRs from multiple vendors. It allows only one copy to run at a time and copies itself to hidden locations on the device. It is added to several startup files so it survives reboots. A second persistence method replaces the system's wget binary with the malware, after moving the original, so the malware runs whenever a legitimate process calls wget.