Threat actors are exploiting a patched Realtek SDK flaw to spread Cling botnet, which uses STUN protocol for stealthy command-and-control. Learn how it works and how to protect your network.
### A Familiar Flaw, A New Twist
Remember the Realtek Jungle SDK vulnerability that made headlines a while back? It was patched, but threat actors haven't moved on. They're now using it to spread a botnet called Cling. This isn't just another malware variant; it's a clever evolution in how attackers stay hidden.
According to a report from Nozomi Networks, Cling stands out not because it uses some fancy new infection method, but because it turns something totally normal—STUN—into a stealthy command-and-control (C2) channel. STUN is a standard protocol used for things like VoIP calls and online gaming. It helps devices figure out their public IP address and type of NAT they're behind. By mimicking legitimate STUN traffic, Cling can slip past many security systems that might otherwise flag suspicious communication.
### How Cling Operates
The attack chain starts with attempts to exploit the Realtek SDK flaw. If successful, the attacker gains a foothold on the device—often a router, camera, or other IoT gadget. From there, they deploy the Cling botnet malware. Once installed, Cling reaches out to its C2 server using STUN messages. These messages look like regular network chatter, making it tough for defenders to spot the malicious traffic.
> "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," the Nozomi Networks report explains.
This approach isn't just sneaky; it's practical. STUN is allowed through many firewalls because it's essential for real-time communications. So, by piggybacking on it, Cling can maintain a low profile while receiving instructions from its operators.
### Why This Matters for Your Security
If you manage network devices—especially IoT ones—this is a wake-up call. The Realtek SDK flaw may be patched, but unpatched devices are still out there. And attackers are counting on that. They're also betting that security teams won't scrutinize STUN traffic closely.
Here's what you can do:
- **Patch immediately**: If you haven't updated devices using the Realtek SDK, do it now. Check with vendors for firmware updates.
- **Monitor STUN traffic**: While STUN is legitimate, unusual patterns—like repeated connections to unfamiliar IPs—could signal Cling. Use network monitoring tools to baseline normal behavior.
- **Segment your network**: Keep IoT devices on separate VLANs to limit lateral movement if one gets compromised.
- **Educate your team**: Make sure everyone knows about this tactic. Sometimes the best defense is simply awareness.
### The Bigger Picture
Cling is a reminder that attackers are constantly innovating. They don't always need zero-days; sometimes they just need to think creatively about existing protocols. As defenders, we need to do the same. Don't ignore the basics—patching, monitoring, and segmentation—but also stay curious about how everyday tech can be twisted for malicious purposes.
So, next time you see STUN traffic, don't just assume it's benign. It might be hiding something more sinister. Stay vigilant, and keep those devices updated. Your network will thank you.