Frequency
4
occurrences
First Seen
October 5, 2026
Last Seen
October 5, 2026
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Threat actors are exploiting a critical vulnerability (CVE-2021-35394) in the Realtek Jungle SDK to deploy a botnet malware named Cling. This malware utilizes STUN traffic to create a covert command-and-control channel, allowing it to blend in with legitimate network activity. The vulnerability, whi...
The ClingSTUN backdoor has been identified as a Linux malware that exploits numerous vulnerabilities in Internet-facing devices, turning them into proxy nodes for remote attackers. It targets flaws in devices from manufacturers like D-Link, TP-Link, and Realtek, utilizing the STUN protocol for NAT t...
Public Exploits
Checking GitHub for proof-of-concept code…