Threat actors have been observed trying to exploit a now-patched critical vulnerability in the Realtek Jungle software development kit (SDK) to deliver a botnet malware known as Cling. The attacks focus on a flaw that has already been fixed, highlighting the continued risk from unpatched devices in the field.
Cling is notable not because it introduces a new propagation technique, but because of its command-and-control approach. The botnet uses STUN, a protocol typically associated with network address translation, to establish its C2 channel. This choice may help the malware blend in with normal traffic and evade detection.
Organizations using devices built on the Realtek Jungle SDK should ensure the latest patches are applied. The observed activity underscores how attackers will revisit known vulnerabilities to expand botnet infections, even after fixes are available.