A botnet called Cling is recruiting unpatched routers and cameras, then hiding its commands inside STUN traffic that looks like ordinary call setup. The activity was reported on 5 October 2026.
What happened
Nozomi Networks saw a spike, from about 5 September 2026, in attempts to exploit CVE-2021-35394. That is a critical remote-code flaw in the Realtek Jungle SDK, patched by Realtek in 2021 and still present on devices that never got firmware. A subset of the attempts delivered Cling.
Cling registers through public STUN servers, the same protocol used for NAT traversal in voice and video calls. Operator commands can be carried so the traffic resembles a normal STUN reply. Fortinet's 5 October write-up tracks the same family as ClingSTUN and describes it as a backconnect proxy that blends with VoIP and WebRTC. The sample also carries exploits for older router and DVR bugs, so Realtek is the entry point, not the only one.
Who is affected
Internet-facing devices still running the vulnerable Realtek SDK, plus other small routers, DVRs, and cameras whose firmware was never updated. This is an edge and branch-office problem more than a domain-controller problem.
- Devices built on Realtek Jungle SDK versions that never received the 2021 fix
- Routers and DVRs with management or diagnostic services exposed to the internet
- Networks that allow outbound UDP to public STUN servers without any review
What to do now
Remove internet exposure on old routers, cameras, and DVRs, and replace firmware that cannot be patched. Alert on new devices sending regular STUN binding requests to unusual servers, especially if the same host also accepts inbound management traffic.
Source: The Hacker News, citing Nozomi Networks and a 5 October Fortinet report.
Also on the blog
- Exchange CVE-2026-96940: signed-in users can read other mailboxes
- ClickFix cache smuggling bypasses the Windows Run character limit
- HPE iLO 7 CVE-2026-79820 scores 9.0 on user validation
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.