Mmastodon TechnologyCybersecurity first seen 7 h ago, last 7 h ago, peak #2
Hackers Exploit Realtek SDK Flaw to Deploy Cling Botnet
Original: ⚠️ CRITICAL: Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 Threat actors are actively expl
Threat actors are actively exploiting CVE-2021-35394, a vulnerability in Realtek's Jungle SDK, to distribute the Cling botnet. The malware disguises its command-and-control traffic as legitimate NAT traffic using the STUN protocol, making it harder to detect. Security researchers warn affected routers and IoT devices should be patched urgently.
Why now: Active exploitation of a known critical vulnerability with novel STUN-based command-and-control hiding is prompting security warnings.
RealtekCling botnetCVE-2021-35394
Evidence
- ⚠️ CRITICAL: Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 Threat actors are actively exploiting CVE-2021-35394 in Realtek Jungle SDK to deploy the Cling botnet, which uses STUN protocol traffic to hide C2 communications as legitimate NAT… · threatnoir@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/1222229