Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteAttackers are again probing a 2021 flaw in the Realtek Jungle SDK, CVE-2021-35394, and some of those attempts end with a router-class device downloading a botnet called Cling. What sets Cling apart is its command channel. It hides operator instructions inside UDP packets shaped like replies from STUN servers, including packets that appear to come from an address Google’s STUN hostname resolves to.
Nozomi Networks Labs published the analysis on October 1, 2026, based on anonymized customer telemetry and one analyzed MIPS sample. The Hacker News covered it on October 5, 2026, and dates the start of the spike to around September 5, 2026. Only a subset of the observed exploit attempts retrieved and ran Cling. The report gives no campaign-wide infection count, and it does not name an actor. This article covers what was observed, how the STUN trick works, and what defenders can check.
What was observed
While monitoring anonymized customer telemetry, Nozomi saw a spike in attempts to exploit CVE-2021-35394. This is a remote-code-execution bug in a diagnostic component of the Realtek Jungle SDK, commonly compiled as UDPServer. Much of the activity looked like opportunistic probing. A subset fetched and executed a Cling sample.
The flaw is old, but it still matters. Realtek SDK components are embedded in devices from many manufacturers, and some of those devices may never have received a fix. The National Vulnerability Database lists a CVSS base score of 9.8 for the CVE. That figure is a severity rating for the vulnerability. It says nothing about how large the Cling campaign is or how many devices are infected.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
For scale on the broader problem, Palo Alto Networks Unit 42 reported 134 million exploit attempts against this CVE between August and December 2022. That is a 2022 figure, years before the Cling activity. It should not be read as a count of Cling infections or as current 2026 volume.
How the attack reaches a device
The exploit traffic
Nozomi describes the exploit as a UDP datagram that begins with orf; followed by shell commands. In a captured attempt, those commands used BusyBox wget to download a binary, marked it executable, and ran it with an infection-method tag such as realtek.selfrep. The tag tells the malware, and presumably the operator, how that bot was acquired.
Exploit logic for seven other flaws
The analyzed MIPS sample also carries exploit code for seven additional command-injection vulnerabilities. They affect devices from Realtek, Eir, MVPower, LB-LINK, FiberHome/China Mobile, TBK and Linksys. This is exploit logic found inside the sample. It does not show that each of those flaws was used in every infection, so the Realtek bug should not be treated as the only way in. Inventory work should cover all of these device families.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
How Cling survives on the device
The analyzed sample uses several persistence mechanisms. Nozomi’s report does not say whether every Cling variant uses all of them.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →| Mechanism | What the sample does | What to look for |
|---|---|---|
| Single-instance check | Binds a socket on port 33957 to see whether another copy is already running | A process listening on UDP/TCP port 33957 on an embedded device. The report describes the bind but not the socket type, so check both. |
| Self-copy | Copies itself to /root/.cling and /usr/local/bin/.cling |
Hidden files named .cling at those paths |
| Startup entries | Adds references in /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot on SysV or BusyBox-style systems |
Unexpected lines in those files that point to a .cling binary |
| wget replacement | Moves the real wget to wget.r, records its location in wget.p, and installs the malware in its place, so later calls to wget can re-execute it |
wget.r and wget.p files next to the wget binary; a wget whose size or hash differs from a known-good firmware image |
How does Cling use STUN for command and control?
STUN (Session Traversal Utilities for NAT) lets a device behind NAT learn its public IP address and the external port the NAT mapped for it. It is common in real-time communications such as voice and video, so STUN traffic to public servers is not unusual on many networks. Cling borrows this ordinary behavior in five steps.
- Binding Requests. The bot sends STUN Binding Requests to a hard-coded list of 13 servers roughly every five seconds. Each request uses an all-zero transaction ID. A normal STUN client uses a random value.
- Learning mapped ports. From the replies, the bot records the external ports the NAT assigned to it.
- Registration. It sends a custom registration datagram carrying those ports and its infection tag. This datagram is not a valid STUN message, and compliant STUN servers ignore it. A server run by the operator can read it.
- Listening. The bot listens on the mapped ports for incoming UDP packets.
- Commands in the transaction ID. Operator commands are encoded in the 12-byte transaction ID field of those packets, so they look like STUN responses.
Nozomi summed it up: “Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel.”
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
The design has a practical benefit for the attacker. Because the NAT mapping is already open, commands can reach the bot without it connecting to a conventional C2 domain or IP address. Traffic aimed at well-known STUN infrastructure is also less likely to stand out in a flow log.
How researchers identified the operator’s server
Nozomi flagged 145.249.115[.]184 because it behaved differently from legitimate STUN servers. When sent controlled Binding Requests with an all-zero transaction ID, it answered with an all-zero ID instead of echoing the ID in the request. In a validation test, the researchers sent different sets of ports to the suspected server and to other listed STUN endpoints. Several hours later they received commands on a port that had been advertised only to the suspected server. On that basis, Nozomi assessed that the server is controlled by, or colluding with, the operator.
The Google address: spoofing, not participation
The command packets appeared to come from 74.125.250[.]129, an address to which stun.l.google.com resolves. That does not mean Google ran the channel or knowingly forwarded commands. Nozomi’s explanation is that the operator most likely spoofed the source IP address. As supporting evidence, the report points to consistent TTL differences between legitimate STUN responses and the command packets. A blocklist or reputation rule keyed on the source address would therefore be unreliable here. Blocking a Google STUN address could also break legitimate applications without stopping the botnet.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
What the bot can be told to do
| Command capability in the analyzed sample | Effect |
|---|---|
| Payload execution | Runs an operator-supplied payload on the device |
| Scanning and exploitation | Searches for and attacks further devices; the operator can also stop the scanner |
| TCP tunnel (start/stop) | Turns the device into a tunnel endpoint |
| Proxy relay (start/stop) | Lets the operator route traffic through the device |
| Flood | Sends traffic at a specified target for a specified duration (denial of service) |
Nozomi observed commands to self-propagate and to flood several targets. For the device owner, the proxy and tunnel functions matter as much as the flooding. A compromised router can be used to mask other attackers’ traffic, and it can become a foothold toward the network behind it.
How can defenders detect Cling on an IoT device?
On the network
- Look for devices sending repeated STUN Binding Requests with an all-zero transaction ID. A repeating pattern about every five seconds to many different public STUN servers is unusual for a router, camera or DVR that has no voice or video role.
- Look for custom, non-STUN UDP datagrams sent to hosts that are otherwise treated as STUN endpoints, such as the registration message with ports and an infection tag.
- Look for inbound UDP packets that mimic STUN responses to ports the device did not request, especially when the source address is a well-known STUN provider. Differences in TTL against genuine responses from that provider can help here.
- Compare each device against its own baseline. A baseline works better than reputation lists for this kind of traffic.
- Watch for inbound UDP datagrams to embedded devices beginning with
orf;, which is the exploit pattern Nozomi captured. - Treat
145.249.115[.]184as a known suspicious indicator. Do not rely on it alone, because other infrastructure may be used.
On the device
- Check for
/root/.clingand/usr/local/bin/.cling. - Review
/etc/inittab,/etc/init.d/rcSand/etc/rc.d/rc.bootfor entries you cannot account for. - Look for
wget.randwget.pbeside thewgetbinary. - Check for a process bound to port 33957.
Many consumer and carrier-supplied devices offer no shell access. In that case, network-side detection and vendor support are the only options. A clean result from these host checks applies to this analyzed sample, and other variants may use different paths or ports.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to do about it
The priorities below follow Nozomi’s guidance. Which one comes first depends on whether a vendor fix exists for the device.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
| Priority | Action | Notes |
|---|---|---|
| 1 | Inventory internet-facing routers, access points, DVRs and other embedded appliances | Include devices from the vendors named in the sample: Realtek-based devices, Eir, MVPower, LB-LINK, FiberHome/China Mobile, TBK and Linksys. Your device list may not show that a model uses a Realtek SDK, so check with the vendor. |
| 2 | Apply vendor firmware updates | The report gives no universal fixed firmware version. Fixes are specific to each OEM and model. |
| 3 | Cut exposure where no update exists | Block unnecessary inbound access from the internet, and consider replacing unsupported equipment. |
| 4 | Segment IoT and edge devices | A compromised router or camera should not be able to reach higher-value systems directly. |
| 5 | Monitor protocol behavior and host artifacts | Use the network and device checks above. |
If you suspect a device is infected, preserve relevant network captures and host evidence before changing anything. Then follow the vendor’s remediation guidance. Nozomi’s report provides no recovery procedure that applies to every OEM device. A factory reset alone is not a safe assumption. Unless the firmware is also patched, the device can be exploited again, since the exposure that let the malware in is unchanged.
What this does and does not show
- It does not show that every device with the vulnerable component is infected, or that every exploit attempt delivered Cling.
- No threat actor is named, and no campaign-wide infection count is given.
- The technical details come from one analyzed MIPS sample plus observations from related samples, so they may not hold for every Cling variant.
- The finding about
145.249.115[.]184is Nozomi’s assessment based on its validation test, not a public admission or a legal attribution.
The main lesson goes beyond this one CVE. An unpatched five-year-old bug is still enough to recruit devices. And since Cling’s control traffic is shaped like a protocol most networks permit, detection depends on checking how a protocol is used, not just where the traffic is going.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

