Malware, Patch/Configuration Management, Threat Intelligence, Vulnerability Management

Cling botnet exploits Realtek SDK flaw, uses STUN for C2

According to The Hacker News, threat actors are exploiting a critical vulnerability in the Realtek Jungle software development kit (SDK) to deploy a botnet malware known as Cling. This malware is notable for repurposing STUN behavior to create a command-and-control channel that can evade network monitoring.

The Cling botnet leverages CVE-2021-35394, a critical remote code execution flaw in the Realtek Jungle SDK, to infect devices. The malware embeds exploit logic for multiple command injection and RCE vulnerabilities affecting routers and DVRs from various vendors, including Realtek, Eir, MVPower, LB-LINK, FiberHome, TBK, and Linksys. To achieve persistence, Cling copies itself to specific directories and appends its executables to system startup files. It also employs a novel persistence mechanism by replacing the 'wget' binary with itself. A key feature of Cling is its use of STUN (Session Traversal Utilities for Network Address Translation) traffic and public STUN infrastructure for command and control. The malware sends STUN Binding Requests to a list of servers, registers itself with custom messages, and receives commands embedded within the STUN transaction ID field. This technique makes the malicious traffic resemble legitimate NAT-traversal activity, effectively hiding C2 communications within seemingly innocuous interactions with STUN servers, even masquerading as replies from legitimate services like stun.l.google.com.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds