Cling botnet hides operator commands inside STUN traffic
Cling botnet STUN command channel on old router bugs

Cling botnet hides operator commands inside STUN traffic

A botnet called Cling is recruiting unpatched routers and cameras, then hiding its commands inside STUN traffic that looks like ordinary call setup. The activity was reported on 5 October 2026.

What happened

Nozomi Networks saw a spike, from about 5 September 2026, in attempts to exploit CVE-2021-35394. That is a critical remote-code flaw in the Realtek Jungle SDK, patched by Realtek in 2021 and still present on devices that never got firmware. A subset of the attempts delivered Cling.

Cling registers through public STUN servers, the same protocol used for NAT traversal in voice and video calls. Operator commands can be carried so the traffic resembles a normal STUN reply. Fortinet's 5 October write-up tracks the same family as ClingSTUN and describes it as a backconnect proxy that blends with VoIP and WebRTC. The sample also carries exploits for older router and DVR bugs, so Realtek is the entry point, not the only one.

Who is affected

Internet-facing devices still running the vulnerable Realtek SDK, plus other small routers, DVRs, and cameras whose firmware was never updated. This is an edge and branch-office problem more than a domain-controller problem.

  • Devices built on Realtek Jungle SDK versions that never received the 2021 fix
  • Routers and DVRs with management or diagnostic services exposed to the internet
  • Networks that allow outbound UDP to public STUN servers without any review

What to do now

Remove internet exposure on old routers, cameras, and DVRs, and replace firmware that cannot be patched. Alert on new devices sending regular STUN binding requests to unusual servers, especially if the same host also accepts inbound management traffic.

Source: The Hacker News, citing Nozomi Networks and a 5 October Fortinet report.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

HPE iLO 7 CVE-2026-79820 scores 9.0 on user validation
HPE iLO 7 remote user validation failure