Executive Summary
In October 2026, threat actors exploited CVE-2021-35394, a critical remote code execution vulnerability in Realtek Jungle SDK, to deploy the Cling botnet malware. The malware demonstrated sophisticated command-and-control capabilities by masquerading malicious traffic as legitimate STUN protocol communications, making it appear as routine NAT-traversal activity. Cling infected routers, DVRs, and IoT devices across multiple vendors, establishing persistence through various mechanisms and enabling operators to conduct denial-of-service attacks, proxy operations, and lateral movement. The botnet's innovative use of public STUN infrastructure, including Google's STUN servers, allowed operators to blend malicious communications with legitimate VoIP and WebRTC traffic, significantly complicating detection efforts.
This incident highlights the evolving sophistication of IoT botnets and their ability to exploit legitimate network protocols for covert operations, representing a significant shift in how threat actors conduct command-and-control communications in 2026.
Why This Matters Now
The Cling botnet represents a new evolution in command-and-control obfuscation techniques, demonstrating how threat actors are increasingly leveraging legitimate protocols like STUN to hide malicious activity within normal network traffic, making detection significantly more challenging for traditional security tools.
Attack Path Analysis
The Cling botnet campaign exploited unpatched Realtek SDK and router vulnerabilities to gain initial access to IoT devices, established persistence through system file modifications, spread laterally by scanning for additional vulnerable devices, maintained command and control through disguised STUN traffic appearing as legitimate Google services, exfiltrated device information and network topology data, and created a distributed botnet capable of DDoS attacks and proxy operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors exploited CVE-2021-35394 and multiple router/DVR RCE vulnerabilities to gain remote code execution on internet-facing devices
Related CVEs
CVE-2021-35394
CVSS 9.8A critical remote code execution vulnerability in Realtek Jungle SDK allows attackers to execute arbitrary code via command injection, affecting numerous router and IoT device manufacturers.
Affected Products:
Realtek Jungle SDK – < 2.0.x
Exploit Status:
exploited in the wildCVE-2014-8361
CVSS 9.8A remote code execution vulnerability in Realtek SDK allows remote attackers to execute arbitrary code via crafted requests to the management interface.
Affected Products:
Realtek SDK – < 2014.12
Exploit Status:
exploited in the wildCVE-2023-46805
CVSS 8.2Authentication bypass vulnerability in Ivanti Connect Secure and Policy Secure allows remote attackers to bypass authentication and access restricted resources.
Affected Products:
Ivanti Connect Secure – < 22.7R2.2
Ivanti Policy Secure – < 22.7R1.1
Exploit Status:
exploited in the wildCVE-2024-21887
CVSS 9.1Command injection vulnerability in Ivanti Connect Secure and Policy Secure allows authenticated attackers to execute arbitrary commands on the underlying operating system.
Affected Products:
Ivanti Connect Secure – < 22.7R2.2
Ivanti Policy Secure – < 22.7R1.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Systemd Timers
Process Injection
Web Protocols
Network Denial of Service
Proxy
Exploitation of Remote Services
Match Legitimate Name or Location
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software engineering techniques or other methods are defined and in use by software development personnel to prevent or mitigate common software attacks and related vulnerabilities
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.10
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Know and Manage Enterprise Assets
Control ID: Asset Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
NIST SP 800-53 – Flaw Remediation
Control ID: SI-2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical exposure to Cling botnet exploiting router vulnerabilities including Realtek SDK, D-Link, TP-Link devices enabling lateral movement and command-and-control infrastructure compromise.
Utilities
Operational technology systems face botnet infiltration through network equipment vulnerabilities, threatening SCADA networks with encrypted traffic exfiltration and east-west segmentation bypasses.
Financial Services
Network infrastructure vulnerabilities enable botnet propagation compromising PCI compliance requirements for encrypted traffic monitoring and zero trust segmentation enforcement mechanisms.
Health Care / Life Sciences
Medical device networks vulnerable to Cling botnet exploitation violating HIPAA encryption requirements while enabling lateral movement through unsegmented healthcare infrastructure systems.
Sources
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.htmlVerified
- A Stunning Disguise: Cling Malware Masquerades as Google STUN Traffichttps://www.nozominetworks.com/blog/a-stunning-disguise-cling-malware-masquerades-as-google-Verified
- ClingSTUN: Linux Backdoor Abuses Public STUN Infrastructurehttps://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructureVerified
- CVE-2021-35394 - National Vulnerability Databasehttps://nvd.nist.gov/vuln/detail/CVE-2021-35394Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would be relevant to this IoT botnet incident by constraining lateral movement between compromised devices and limiting the scope of coordinated attacks through network segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial device compromise would likely still occur, but the blast radius and reachability to other network segments would be constrained through identity-aware network policies
Control: Zero Trust Segmentation
Mitigation: While local privilege escalation may still succeed, the scope of access would likely be limited to the immediate device workload without broader network privileges
Control: East-West Traffic Security
Mitigation: Lateral scanning and propagation attempts would likely be constrained by east-west traffic controls, reducing the malware's ability to reach and compromise additional devices
Control: Multicloud Visibility & Control
Mitigation: C2 communications would likely face increased scrutiny and potential blocking through enhanced visibility into traffic patterns and destination controls across cloud environments
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained through controlled egress policies that limit outbound destinations and inspect traffic for unauthorized data transmission
The coordinated attack capability would likely be reduced in scope due to fewer successfully compromised devices and constrained network paths for attack traffic generation
Impact at a Glance
Affected Business Functions
- Network Infrastructure Management
- IoT Device Operations
- Internet Connectivity Services
- Network Security Monitoring
Estimated downtime: 7 days
Estimated loss: N/A
Network traffic data, device configuration information, and potentially sensitive communications routed through compromised router and IoT devices acting as proxy nodes in the botnet infrastructure
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Inline IPS with signature-based detection to block known exploit patterns targeting IoT device vulnerabilities at network ingress points
- • Implement Zero Trust Segmentation to isolate IoT devices and prevent lateral movement between network zones using identity-based policies
- • Enable Egress Security & Policy Enforcement to detect and block unauthorized outbound STUN traffic patterns and command-and-control communications
- • Establish Multicloud Visibility & Control to identify anomalous IoT device behaviors and suspicious automation patterns across hybrid environments
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal IoT traffic and alert on deviation from expected communication patterns



