INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Hackers Abuse STUN Protocol to Install ClingSTUN Linux Backdoor

| 2026-10-05 22:44 CRITICAL HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
A Linux malware strain named ClingSTUN exploits unpatched vulnerabilities in Internet-facing devices to establish persistent footholds and functions as a back-connect proxy backdoor, targeting IoT devices through multiple CVEs including command injection and code execution flaws. The threat actor abuses legitimate public STUN infrastructure to discover externally mapped IP addresses, maintain NAT bindings, and improve connectivity between compromised hosts and operators. ClingSTUN maintains remote command execution capabilities and includes self-propagation exploits for seven additional vulnerabilities. As of October 5th, 2026, the affected entities include at least 99b9893064d39dd314ea691adf3281cc0aa7e0a31e5138adfb6008a2c828a9cb62342aec53006ae05a60cb8d4c41c3fa216fd727e8c6a3, with IP addresses [IOC HIDDEN • LOGIN REQUIRED] and [IOC HIDDEN • LOGIN REQUIRED] also being compromised. The attack works by exploiting vulnerabilities in various vendors' products to establish a persistent foothold on the compromised hosts, which then use legitimate public STUN infrastructure to maintain connectivity with operators.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-91843, CVE-2026-20079 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Pre-compromise (ATT&CK mitigation for Botnet): This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

9391c6••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
90d738••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
dfba60••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
b037f4••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
li•••••.tmp
ww•••••.com
cm•••••.jar
om•••••.pl
so•••••.py
222.223.•••.•••
118.45.•••.•••
118.145.•••.•••
83.211.•••.•••
d8352c••••••••••••••••••••••••••••••••••
3b0ac6••••••••••••••••••••••••••••••••••
08636d••••••••••••••••••••••••••••••••••
945649••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
85d9be••••••••••••••••••••••••••
26cec4••••••••••••••••••••••••••
89b400••••••••••••••••••••••••••
852633••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Star BlizzardStar Blizzard NotPetyaNotPetyaQilinQilinCyclops BlinkCyclops Blink CVE-2026-91843CVE-2026-91843 CVE-2026-20079CVE-2026-20079 CVE-2026-20212CVE-2026-20212 CVE-2026-85103CVE-2026-85103 CVE-2026-73456CVE-2026-73456 CVE-2026-20293CVE-2026-20293 CVE-2026-76460CVE-2026-76460 CVE-2026-85102CVE-2026-85102 CVE-2026-83548CVE-2026-83548 CVE-2026-33197CVE-2026-33197 CVE-2026-6485CVE-2026-6485 CVE-2026-73453CVE-2026-73453 CVE-2026-31431CVE-2026-31431 CVE-2026-20316CVE-2026-20316 CVE-2021-35394CVE-2021-35394 CVE-2026-83549CVE-2026-83549
Target & Sectors
NORTH_AMERICA NORTH_AMERICA energyenergy governmentgovernment
Incident Timeline
‎late July 2026
Threat actors added CVE-2026-20316 to the KEV catalog in late July 2026.
vulnerability CVE-2026-20316
organisation KEV
‎July 29
BleepingComputer previously reported on July 29 that Cisco had updated the CVE-2026-20079 advisory with hot fixes and indicators of compromise.
vulnerability CVE-2026-20079
vulnerability CVE-2026-20316
organisation BleepingComputer
‎September 2
CISA added both vulnerabilities to its KEV catalog on September 2, which SonicWall has since confirmed are being exploited in attacks.
attribution KEV
attribution CISA
attribution SonicWall
‎2026/09/07
Threat actors exploited 24 IoT vulnerabilities to install a ClingSTUN Linux backdoor, prompting Cisco to release hotfixes and advise affected organizations to apply them immediately.
industry Technology
‎September 9
Threat actors exploited 24 IoT vulnerabilities to install a ClingSTUN Linux backdoor, with Cisco and Arista confirming the attacks on September 9.
tactic Remote Code Execution
organisation EOS
general_metric 34 security advisories
organisation Product Security Incident Response Team
‎Sep 11, 2026
Threat actors exploited 24 known IoT vulnerabilities to install a ClingSTUN Linux backdoor.
‎September 12, 2026
Threat actors exploited 24 IoT vulnerabilities to install a ClingSTUN Linux backdoor, which was subsequently added to the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog.
tactic T1588.006 - Vulnerabilities
attribution KEV
vulnerability CVE-2026-20079
attribution Known Exploited
attribution Federal Civilian Executive Branch
attribution FCEB
‎Week of September 14th
Threat actors are scheduled to exploit 24 IoT vulnerabilities, including those addressed in a forthcoming hardening release, starting the week of September 14th.
‎September 16
Threat actors exploited 30 vulnerabilities in Cisco's Internet Security Engine (ISE) and Firepower Management Center (FMC) products on September 16.
‎Week of September 16th
Threat actors are scheduled to exploit 24 IoT vulnerabilities, including those addressed in a forthcoming hardening release, starting the week of September 16th.
‎October 5, 2026
Threat actors exploited 24 known IoT vulnerabilities to install a ClingSTUN Linux backdoor on affected devices.
‎Monday, October 5, 2026
Hackread.com shared a report about hackers exploiting approximately 24 IoT vulnerabilities to install a ClingSTUN Linux backdoor, which occurred on Monday, October 5, 2026.
organisation Hackread.com
‎Between August 25 and September 17
Threat actors exploited 24 IoT vulnerabilities to install a ClingSTUN Linux backdoor between August 25 and September 17.
general_metric 158 new security advisories
general_metric 17 vendors
general_metric 1,699 vulnerabilities
‎2026/10/05
Threat actors used ClingSTUN Linux backdoor to exploit dozens of vulnerabilities in Internet-facing infrastructure, including Cisco Secure Firewall Management Center (FMC) flaws and STUN protocol abuses.
organisation IoT
organisation IP
infrastructure Linux
organisation STUN
organisation NAT
organisation Hackers Exploit
organisation Install ClingSTUN Linux Backdoor
organisation Sophos Counter Threat Unit
organisation Sandworm
organisation TCP
organisation CVE-2026-73453
organisation Google
organisation China Mobile
organisation KGUARD
organisation Linksys
organisation MVPower
organisation Intel
organisation MIPS
organisation AMD
infrastructure Macos
organisation Fake Zoom Installer Carrying
threat_actor Star Blizzard
organisation ClickFix Attacks
organisation Firewall Management Center
organisation Iron Viking
organisation Russian APT
organisation Ivanti
organisation Avtech
organisation EnGenius
organisation Linear
organisation Sunhillo
organisation EnGenius Hytec
organisation Tenda
organisation CVE-2026
organisation Remote Access and Site-to-Site VPN
organisation UDP
organisation Initial Access
organisation Sandworm'
organisation Separate Cisco FMC
organisation Cyclops Blinks
organisation Secure FMC
organisation FortiGuard
organisation Juniper, Extreme Networks
organisation Dell
organisation PowerFlex
organisation PowerProtect
organisation Networking
organisation Cisco FMC Flaws Exploited
organisation FMC
financial 3 Cluster
organisation AV
organisation Invoke-TheHash
organisation CVSS
organisation Appliance Management Console
organisation Cisco Secure Firewall Management Center
infrastructure 10.0
organisation Cisco
organisation Cisco’s Secure FMC
financial 1 Cluster
organisation Attacker
organisation Cisco Secure FMC
organisation Makeself
organisation Maximum Severity
organisation WatchGuard
organisation ASUS
organisation Sophos
organisation CPU
organisation Modular
organisation DNS
organisation HTTPS (DoH
organisation API
organisation Cisco Nexus
organisation CVE-2026-33197
organisation AMI Aptio
organisation InfraTrust
organisation Eclypsium
organisation InfraTrust Pulse
organisation Cisco Identity Services Engine
organisation EdgeConnect SD-WAN Orchestrator
organisation Arista
organisation Check Point
organisation The Dutch Nationaal Cyber Security Centrum
organisation UEFI
organisation Shell
organisation AMI
organisation Lenovo
organisation Supermicro
organisation NFL
organisation CHANEL
organisation Cisco FMC
organisation Hostname
organisation ADFS
organisation LOTL
organisation Secure Firewall Management Center
organisation users;\
organisation UAT-12197 cmd[.]jar
organisation JSP
organisation JAR
organisation APT
financial 2 Cluster
organisation Sandworm APT
organisation ELF
organisation SSH
organisation license[.]tmp
organisation SMB
organisation NETBIOS
data_breach 445 SMB
data_breach 135 NETBIOS
organisation TAC
organisation Attacker IP
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎Ivanti
Affected Product
Metrics
infrastructure
‎10.0
Software Version
Metrics
financial
3
Cluster
Metrics
financial
1
Cluster
Metrics
financial
2
Cluster
Metrics
data_breach
445
Smb
Metrics
data_breach
135
Netbios