Threat actors are actively exploiting a critical vulnerability in the Realtek Jungle SDK (CVE-2021-35394) to distribute a botnet malware known as Cling (or ClingSTUN). This malware is particularly notable for its sophisticated use of the Session Traversal Utilities for NAT (STUN) protocol to establish command-and-control (C2) channels. By embedding malicious traffic within harmless-looking STUN packets and utilizing public STUN infrastructure, the botnet can evade traditional network monitoring that expects such traffic to be legitimate NAT-traversal activity.
Once a device is compromised, Cling achieves persistence through several methods, including modifying system init scripts or hijacking the wget binary. The malware functions as a backconnect proxy and a worm, carrying a library of exploits for various routers and DVRs to facilitate self-propagation. Beyond expanding its reach, the botnet is used to launch denial-of-service attacks and create encrypted tunnels, often making its commands appear as if they are originating from reputable services like Google's STUN servers.
Top comments (0)