Interestana
Home/News/Realtek SDK Exploit Deploys Cling Botnet Via STUN
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Realtek SDK Exploit Deploys Cling Botnet Via STUN

Realtek SDK Exploit Deploys Cling Botnet Via STUN

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware named Cling. This vulnerability, identified and subsequently patched, allowed attackers to gain unauthorized access and install the Cling botnet on affected devices. The Cling botnet is particularly noteworthy for its innovative approach to command and control (C2) communication, repurposing the Session Traversal Utilities for NAT (STUN) protocol. Nozomi Networks, in a report detailing these findings, highlighted that Cling's significance lies not in novel propagation methods but in its practical application of STUN behavior for C2 channels. STUN is a network protocol used to discover the public IP address and port that a network address translation (NAT) device, such as a router, assigns to a network connection. Typically, STUN is used to enable peer-to-peer connections in applications like VoIP and video conferencing, allowing devices behind NAT to communicate directly. By leveraging STUN for C2, the Cling botnet can establish a communication channel that is more resilient to detection and blocking by traditional network security measures. This method allows the botnet's controllers to issue commands to infected devices and receive data without relying on easily identifiable C2 servers or ports. The exploitation of the Realtek Jungle SDK indicates a targeted effort to compromise devices utilizing this specific development kit. Realtek is a multinational fabless semiconductor company that produces a wide range of integrated circuits and system solutions, including Ethernet controllers, Wi-Fi chips, and audio codecs, which are commonly found in networking equipment, consumer electronics, and embedded systems. The Jungle SDK is a software development kit designed to facilitate the development of applications and firmware for Realtek's networking and IoT devices. Exploiting a vulnerability in such a widely used SDK can have broad implications for the security of numerous connected devices. The report from Nozomi Networks suggests that the attackers are actively using this exploit in the wild, underscoring the urgency for organizations and individuals to ensure their Realtek-based devices are updated with the latest security patches. The successful deployment of the Cling botnet through this method demonstrates a sophisticated understanding of network protocols and an ability to adapt them for malicious purposes. The use of STUN for C2 represents a growing trend in botnet development, where attackers seek to evade detection by blending malicious traffic with legitimate network protocols. This tactic makes it more challenging for security analysts to identify and mitigate botnet activity. Further analysis of the Cling botnet's operations and the specific details of the Realtek SDK vulnerability are crucial for developing effective countermeasures against this evolving threat.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next