According to The Hacker News, threat actors are exploiting a critical vulnerability in the Realtek Jungle software development kit (SDK) to deploy a botnet malware known as Cling. This malware is notable for repurposing STUN behavior to create a command-and-control channel that can evade network monitoring.
The Cling botnet leverages CVE-2021-35394, a critical remote code execution flaw in the Realtek Jungle SDK, to infect devices. The malware embeds exploit logic for multiple command injection and RCE vulnerabilities affecting routers and DVRs from various vendors, including Realtek, Eir, MVPower, LB-LINK, FiberHome, TBK, and Linksys. To achieve persistence, Cling copies itself to specific directories and appends its executables to system startup files. It also employs a novel persistence mechanism by replacing the 'wget' binary with itself. A key feature of Cling is its use of STUN (Session Traversal Utilities for Network Address Translation) traffic and public STUN infrastructure for command and control. The malware sends STUN Binding Requests to a list of servers, registers itself with custom messages, and receives commands embedded within the STUN transaction ID field. This technique makes the malicious traffic resemble legitimate NAT-traversal activity, effectively hiding C2 communications within seemingly innocuous interactions with STUN servers, even masquerading as replies from legitimate services like stun.l.google.com.
Source: The Hacker News
