Threat actors are exploiting flaws associated with the Realtek Jungle SDK — the library behind a vast installed base of consumer and SOHO network devices — to deliver an emerging Cling botnet that uses STUN (Session Traversal Utilities for NAT)-based command and control, a technique that lets malware establish outbound connectivity and receive instructions in a way that is substantially harder to spot in traffic inspection than conventional HTTP C2. Exploit attempts observed against the SDK aim to compromise embedded devices and recruit them into the botnet, extending a longstanding attack surface on cheap routers, IP cameras and IoT gear. The C2-over-STUN design reduces tell-tale outbound signalling, and the botnet is positioned for use in later malicious activity. Why it matters: with Realtek Jungle SDK components present on millions of devices globally — including in Australian homes and small offices — unpatched embedded devices are a standing gateway into Cling, and STUN-based C2 makes the infection harder to detect on networks that do not baseline NAT traversal traffic.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-06 |
| Source | The Hacker News |
| Reliability | Tier 2 |