Skip to content

Security1 publisher2 min readPublished

Attackers keep exploiting a five-year-old Realtek flaw to spread the Cling botnet

Nozomi Networks reports a September 5 spike in attacks exploiting CVE-2021-35394, a Realtek SDK flaw patched five years ago, to plant the Cling botnet. Its command-and-control hides inside ordinary STUN traffic, so the beacons resemble legitimate NAT traversal.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • The sample carries exploit code for seven router and DVR flaws from several vendors, the oldest a 2014 Realtek SDK bug and the newest a 2025 Linksys bug.
  • For persistence it binds a lock on port 33957, copies itself to hidden paths, and appends startup entries to inittab and the rc init scripts used by SysV and BusyBox.
  • A fallback method swaps out the system wget binary and hides the original, so the malware runs whenever a legitimate process calls wget.
  • Operator commands let it scan and spread worm-style, open or close TCP tunnels, run or stop a proxy, and flood a chosen target for a set time.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The weak point is edge hardware owners never updated; the Realtek fix shipped long ago but never reached the machines still being taken over.
  • constraint Teams that allowlist UDP to public STUN servers now have a blind spot, since Cling's check-ins and commands ride those same servers.
  • precedent Turning a standard protocol's own fields into a command channel gives other botnet authors a working model that slips past signature-based detection.

STUN exists to help devices stuck behind a NAT or firewall set up direct peer-to-peer connections. [6] Cling turns that handshake into its control channel. The sample sends a STUN Binding Request to 13 hard-coded servers about every five seconds, sets the transaction ID to all zeros instead of the random value the specification requires, and records the public IP and ports each server reports back. [7] It then sends every server a custom UDP message carrying those mapped ports and a tag that records how the box was infected, such as realtek.selfrep or selfrep.router. [8] After that it waits, polling for UDP packets that carry operator commands inside the STUN transaction ID field. [9]

The custom registration messages do not conform to the STUN specification, so legitimate servers drop them. [10] One address in the list, 145.249.115[.]184, does not: it answers with an all-zero transaction ID rather than echoing the request, which Nozomi takes as a server built for the botnet and used to send commands back to the bots. [11] Because the registration goes to every server in the list, Nozomi concluded the operator needs visibility into at least one of them to track new bots and know where to send commands. [13]

To a monitoring tool, none of this looks wrong. "From a network monitoring perspective, the activity appears as innocuous interaction with STUN servers," Nozomi Networks said. [12] The company placed the significance on the method. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said. [4]

What to watch

  • Whether exploit attempts broaden from CVE-2021-35394 to the newer embedded bugs such as the 2025 Linksys flaw.
  • Whether the operator-controlled STUN server at 145.249.115[.]184 gets sinkholed or pulled, cutting command delivery.
  • Whether new infection tags beyond realtek.selfrep and selfrep.router appear, signaling spread to other device classes.
Loading claim ledger
Loading source directory links
Loading share composer