Technology newsroom
π¨ Alert! Realtek SDK Vulnerability Exploited to Install Cling Botnet via New C2 Technique
Hackers are exploiting a vulnerability in Realtek Jungle SDK to spread Cling Botnet malware, which utilizes a novel technique employing the STUN protocol as its Command-and-Control (C2) channel, making detection more difficult.
π Key Takeaways:
- Hackers are exploiting a previously patched security vulnerability in the Realtek Jungle SDK.
- The objective is to install Cling Botnet malware, which has a unique ability to communicate back to its command server.
- Cling Botnet employs an interesting technique by using the STUN (Session Traversal Utilities for NAT) protocol as its Command-and-Control (C2) channel to evade detection.
Cybersecurity research firm Nozomi Networks has unveiled a new attack campaign where malicious actors are attempting to exploit a critical, previously discovered and patched vulnerability in Realtek's software development kit (SDK), specifically the Jungle SDK, to install Cling Botnet malware.
Despite a patch being available for this vulnerability, numerous network and IoT devices worldwide have not updated their firmware, leaving them highly susceptible to attacks. The Realtek SDK vulnerability is an attractive target for hackers because Realtek chips are widely used in a vast number of network devices, ranging from routers and access points to various IoT devices.
π‘ The Uniqueness of Cling Botnet
What makes Cling Botnet interesting and dangerous is not a new propagation technique, but rather the method it employs to communicate with its Command-and-Control (C2) server. Nozomi Networks reports that Cling has adapted the STUN protocol, which is typically used to help devices behind NAT communicate with external networks (e.g., in VoIP or video call systems), to serve as its own C2 channel.
The use of STUN traffic, which appears to be normal traffic, makes detecting this botnet's activity significantly more difficult for traditional security systems, as they might perceive it as legitimate communication according to standard protocols. This action demonstrates hackers' continuous efforts to find new ways to evade detection.
Therefore, it is recommended that system administrators and general users check and update the firmware of network devices using Realtek chips to the latest version as soon as possible, in order to close the vulnerability and prevent the risk of becoming part of a botnet network.
π¬ Have you checked if the firmware on your router or IoT devices at home/work is up to date? Share your thoughts with us.