Back to Intelligence

ClickFix, ClingSTUN, and MALFEX: Defending Against Newsletter Round 118's Multi-Platform Threat Wave

SA
Security Arsenal Team
October 11, 2026
11 min read

The latest Security Affairs malware research roundup (Round 118) is a snapshot of where the threat landscape actually sits in 2026: attackers are abandoning noisy exploit delivery in favor of living-off-the-user and living-off-the-ecosystem techniques. Four stories from this round deserve immediate attention from defenders:

  1. ClingSTUN — a Linux unauthorized-access mechanism that abuses public STUN infrastructure (the same Session Traversal Utilities for NAT services that power legitimate VoIP and WebRTC) for covert command-and-control, blending C2 traffic into normal-looking UDP/3478 flows.
  2. UAC-0277's ClickFix campaign — compromised websites serving fake CAPTCHA/verification pages that trick users into pasting malicious commands into the Windows Run dialog, delivering the LUNEXSTEALER infostealer.
  3. MALFEX — a malicious npm package whose postinstall hook executed hostile payloads for fourteen months without triggering a single registry advisory, a brutal reminder that dependency trust is still an unmonitored blind spot in most pipelines.
  4. PoeLLM ("Canto incognito") — malware abusing LLM-adjacent infrastructure, continuing the trend of attackers riding AI tooling adoption.

None of these rely on a patchable CVE. They exploit trust: trust in public infrastructure, trust in what a website tells a user to type, and trust in the package registry. That's precisely why signature-only defenses keep missing them — and why behavioral detection is the focus of this post.

Technical Analysis

UAC-0277 ClickFix → LUNEXSTEALER (Windows)

Attack chain: The actor compromises legitimate websites and injects overlay pages mimicking CAPTCHA or "Verify you are human" checks. The page instructs the victim to press Win+R, paste (via clipboard hijack — the page pre-populates the clipboard with a malicious one-liner), and hit Enter. The pasted command is typically a PowerShell or mshta.exe invocation that retrieves a second-stage payload, culminating in LUNEXSTEALER deployment — an infostealer harvesting browser credentials, cookies/session tokens, cryptocurrency wallets, and system fingerprints.

Key defensive observation: this technique produces a highly distinctive process lineage. Legitimate software almost never results in explorer.exe (the Run dialog's parent) spawning powershell.exe, pwsh.exe, mshta.exe, or curl.exe with remote-fetch arguments. That lineage is the detection pivot.

Affected platforms: Windows 10/11 and Server editions — anything with a Run dialog and PowerShell. Exploitation status: confirmed active in the wild via compromised-site injection; no CVE, no KEV entry — this is a social-engineering TTP, not a vulnerability.

ClingSTUN (Linux C2 via Public STUN)

Attack chain: After gaining initial unauthorized access to Linux hosts, the implant establishes command-and-control by abusing public STUN servers (UDP/TCP 3478, TLS 5349). Because STUN is a legitimate, widely deployed NAT-traversal protocol, egress to well-known STUN endpoints rarely trips egress filters or raises analyst eyebrows. The attacker tunnels tasking and exfil inside STUN-shaped traffic.

Key defensive observation: on servers, almost nothing legitimate talks to STUN. STUN is a client-side protocol — desktops running WebRTC/VoIP apps use it; web servers, database hosts, and containers do not. A server-side process with no WebRTC/VoIP role initiating outbound 3478/5349 connections is a high-fidelity anomaly.

MALFEX (npm Supply-Chain, postinstall Hook)

Attack chain: A typosquatted/malicious npm package ships a postinstall script in package.json. The moment a developer or CI runner executes npm install, the hook runs arbitrary code — no user interaction beyond the install itself. Fourteen months without an advisory means the package likely used environment gating (detonating only in CI/production-like environments) and staged payload retrieval to evade static scanning.

Key defensive observation: node/npm spawning shells, network fetchers (curl, wget, powershell), or credential-file access during install is anomalous for the overwhelming majority of packages. Lockfile integrity and --ignore-scripts are your primary controls.

PoeLLM / "Canto incognito"

Details are still emerging, but the pattern matches a growing class of malware piggybacking on LLM-tooling adoption — abusing AI API endpoints, developer-side tooling, or poisoned model-adjacent packages for persistence and exfil. The defensive lesson: apply the same egress monitoring and process-lineage scrutiny to AI developer tooling that you (should) apply to npm.

Detection & Response

Sigma Rules

YAML
---
title: ClickFix Run Dialog Script Execution - LUNEXSTEALER Delivery
description: Detects explorer.exe (Run dialog) spawning script interpreters or fetch tools with remote-retrieval arguments, consistent with UAC-0277 ClickFix social engineering delivering LUNEXSTEALER.
references:
  - https://securityaffairs.com/200775/breaking-news/security-affairs-malware-newsletter-round-118.html
  - https://attack.mitre.org/techniques/T1204/002/
  - https://attack.mitre.org/techniques/T1059/001/
author: Security Arsenal
id: 3f9c1a72-8b44-4e21-9d5a-2c7e6f0a1b93
status: experimental
date: 2026/04/10
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\explorer.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\mshta.exe'
      - '\curl.exe'
      - '\wscript.exe'
      - '\cscript.exe'
  selection_cmdline:
    CommandLine|contains:
      - 'http://'
      - 'https://'
      - 'Invoke-Expression'
      - 'iex '
      - 'Invoke-WebRequest'
      - 'iwr '
      - 'DownloadString'
      - 'FromBase64String'
      - ' -enc '
      - ' -e '
  condition: all of selection_*
falsepositives:
  - Rare; administrators pasting commands into Run dialog is atypical in managed environments
level: high
---
title: npm or node Spawning Shell or Network Fetcher During Install
description: Detects npm/node processes spawning shells or network retrieval utilities, consistent with malicious postinstall hooks such as MALFEX.
references:
  - https://securityaffairs.com/200775/breaking-news/security-affairs-malware-newsletter-round-118.html
  - https://attack.mitre.org/techniques/T1195/002/
author: Security Arsenal
id: 7b2e4d61-1a9f-4c38-b502-9e3d8c7f2a46
status: experimental
date: 2026/04/10
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\node.exe'
      - '\npm.cmd'
      - '\npm.exe'
      - '\npx.cmd'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\cmd.exe'
      - '\curl.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
      - '\wscript.exe'
  condition: all of selection_*
falsepositives:
  - A small number of legitimate packages with native build steps (node-gyp); baseline per pipeline and allowlist known-good packages
level: high
---
title: Server Process Initiating Outbound STUN Connection
description: Detects processes on Linux servers initiating connections to STUN ports (3478/5349), consistent with ClingSTUN abusing public STUN infrastructure for C2. Tune to exclude legitimate WebRTC/VoIP workloads.
references:
  - https://securityaffairs.com/200775/breaking-news/security-affairs-malware-newsletter-round-118.html
  - https://attack.mitre.org/techniques/T1071/001/
  - https://attack.mitre.org/techniques/T1572/
author: Security Arsenal
id: c5a8f309-6d21-4b74-a1e8-4f2b9d0c3e57
status: experimental
date: 2026/04/10
logsource:
  category: network_connection
  product: linux
detection:
  selection_port:
    DestinationPort:
      - 3478
      - 5349
  filter_known_rtc:
    Image|endswith:
      - '/chrome'
      - '/firefox'
      - '/zoom'
      - '/asterisk'
      - '/freepbx'
      - '/teams'
  condition: selection_port and not filter_known_rtc
falsepositives:
  - Legitimate VoIP/WebRTC services (Asterisk, FreeSWITCH, coturn); exclude known RTC infrastructure by host group
level: medium

KQL (Microsoft Sentinel / Defender)

KQL — Microsoft Sentinel / Defender
// Hunt 1: ClickFix lineage - Run dialog (explorer) spawning script/fetch tools
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName =~ "explorer.exe"
| where FileName in~ ("powershell.exe","pwsh.exe","mshta.exe","curl.exe","wscript.exe","cscript.exe")
| where ProcessCommandLine has_any ("http://","https://","iex","Invoke-WebRequest","iwr ","DownloadString","FromBase64String"," -enc")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessCommandLine, SHA256
| order by TimeGenerated desc;

// Hunt 2: npm/node spawning shells or fetchers (MALFEX-style postinstall abuse)
DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName in~ ("node.exe","npm.cmd","npm.exe","npx.cmd")
| where FileName in~ ("powershell.exe","cmd.exe","curl.exe","certutil.exe","bitsadmin.exe","wscript.exe","bash.exe","sh.exe")
| project TimeGenerated, DeviceName, AccountName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, FolderPath
| order by TimeGenerated desc;

// Hunt 3: Linux hosts with outbound STUN (3478/5349) from non-RTC processes (ClingSTUN) - via Syslog/CEF ingestion
CommonSecurityLog
| where TimeGenerated > ago(14d)
| where DestinationPort in (3478, 5349)
| where DeviceAction !in ("deny","blocked")
| summarize ConnectionCount = count(), DistinctDestinations = dcount(DestinationIP), Destinations = make_set(DestinationIP, 20) by SourceHostName, SourceIP, DestinationPort, bin(TimeGenerated, 1d)
| order by ConnectionCount desc;

// Hunt 4: Defender network events to STUN ports from server-class devices
DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemotePort in (3478, 5349)
| where ActionType == "ConnectionSuccess"
| where InitiatingProcessFileName !in~ ("chrome.exe","firefox.exe","msedge.exe","Teams.exe","Zoom.exe")
| summarize Connections = count(), RemoteIPs = make_set(RemoteIP, 20) by DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, bin(TimeGenerated, 1d)
| order by Connections desc;

Velociraptor VQL

VQL — Velociraptor
-- Hunt: ClickFix-style execution lineage and postinstall abuse artifacts
-- Part A: Processes whose parent is explorer with script/fetch tooling and remote URLs
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime,
       get_member(field='Exe') AS ProcessPath
FROM pslist()
WHERE CommandLine =~ '(?i)(https?://|FromBase64String|DownloadString|Invoke-Expression|iex | -enc)'
  AND Name =~ '(?i)(powershell|pwsh|mshta|curl|wscript|cscript)'

-- Part B: npm/node parents spawning shells (MALFEX-style postinstall)
SELECT Pid, Ppid, Name, CommandLine, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)(powershell|cmd|curl|certutil|sh|bash)'
  AND Ppid IN (
       SELECT Pid FROM pslist()
       WHERE Name =~ '(?i)(node|npm|npx)'
     )

-- Part C: npm lifecycle scripts present in recently modified node_modules (triage artifact)
SELECT FullPath, Mtime, Size
FROM glob(globs='C:\Users\*\**\node_modules\**\package.json')
WHERE Mtime > timestamp(epoch=win32time_to_unix(now() - 12096000000000))

Remediation / Hardening Scripts

PowerShell
# ClickFix / LUNEXSTEALER hardening + verification (run elevated)
# 1) Audit RunMRU for evidence of pasted commands (ClickFix artifacts live here)
Get-ChildItem 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -ErrorAction SilentlyContinue |
  ForEach-Object { $_.Property } | ForEach-Object {
    $v = (Get-ItemProperty 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU').$_
    if ($v -match 'http|iex|Invoke|certutil|bitsadmin|mshta') {
      Write-Warning "Suspicious RunMRU entry: $_ = $v"
    }
  }

# 2) Enforce PowerShell Constrained Language + Script Block Logging on endpoints
Set-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Name EnableScriptBlockLogging -Value 1 -Force
New-Item 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription' -Force | Out-Null
Set-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription' -Name EnableTranscripting -Value 1 -Force

# 3) Disable mshta via WDAC/AppLocker is ideal; at minimum enable audit of mshta execution
auditpol /set /subcategory:"Process Creation" /success:enable /failure:enable

# 4) Verify no unauthorized outbound STUN from Windows hosts (defense-in-depth)
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
  Where-Object { $_.RemotePort -in 3478,5349 } |
  Select-Object LocalAddress,RemoteAddress,RemotePort,OwningProcess,
    @{N='Process';E={(Get-Process -Id $_.OwningProcess).ProcessName}}
Bash / Shell
#!/bin/bash
# ClingSTUN / MALFEX hardening for Linux servers and build runners
# 1) Identify current outbound STUN connections from non-RTC processes
ss -uapn | awk '$5 ~ /:(3478|5349)$/ {print}'

# 2) Egress-filter STUN on server VLANs (keep only on designated RTC hosts)
# iptables -A OUTPUT -p udp --dport 3478 -j LOG --log-prefix "STUN-EGRESS: "
# iptables -A OUTPUT -p udp --dport 3478 -j DROP
# iptables -A OUTPUT -p tcp --dport 3478:5349 -j DROP

# 3) Alert historically: search auth/syslog for repeated STUN destinations
grep -Ei '3478|5349' /var/log/syslog* 2>/dev/null | tail -50

# 4) npm supply-chain hardening: disable lifecycle scripts globally on CI/dev hosts
npm config set ignore-scripts true --location=global
echo 'ignore-scripts=true' > ~/.npmrc

# 5) Audit installed trees for postinstall hooks (MALFEX-style)
find . -name package.json -path '*node_modules*' -mtime -60 2>/dev/null | \
  xargs grep -l '"postinstall"' 2>/dev/null

# 6) Verify lockfile integrity before installs in CI
npm ci --ignore-scripts --audit --audit-level=high

Remediation

UAC-0277 ClickFix / LUNEXSTEALER:

  • User intervention control: There is no patch — the "vulnerability" is the user. Update security awareness training this quarter with the ClickFix pattern: no legitimate website will ever ask a user to press Win+R and paste a command. This single message kills the technique.
  • Technical controls: Deploy AppLocker/WDAC rules blocking mshta.exe for standard users; enforce PowerShell Constrained Language Mode via WDAC; enable Script Block Logging and forward Event ID 4104 to your SIEM.
  • Web filtering: Block newly registered domains and uncategorized sites at the proxy for the initial lure; the compromised-site overlay stage depends on injected JS on legitimate sites, so script-level protections (browser isolation for uncategorized sites) are the effective compensating control.
  • If executed: Assume credential and session-token theft. Revoke all active sessions for the affected identity (Entra ID / IdP), force password resets, rotate API keys accessible from the host, and reimage — LUNEXSTEALER-class stealers are frequently followed by hands-on intrusions.

ClingSTUN:

  • Add UDP/TCP 3478 and 5349 to your egress deny list for all server VLANs; permit only designated RTC infrastructure.
  • Hunt historically (30–90 days) for any server-sourced STUN connections — C2 via public infrastructure leaves no malicious domain to pivot on, so volume and periodicity (beacon-like regularity to a fixed STUN endpoint) are your analytical pivots.
  • For hosts showing suspicious STUN egress: isolate, capture memory, and triage persistence (cron, systemd units, ld.so.preload, SSH authorized_keys) before remediation.

MALFEX / npm supply chain:

  • Set ignore-scripts=true in .npmrc across developer workstations and CI runners; re-enable per-package only via an allowlist for packages that genuinely need native builds.
  • Use npm ci (not npm install) in CI, pin exact versions, and commit lockfiles. Diff lockfile changes in PR review — a surprise postinstall addition is a red flag.
  • Scan lockfiles against advisories continuously; MALFEX's 14-month advisory gap proves that advisory-only detection is insufficient — pair it with behavioral install-time monitoring (the Sigma/KQL above) and egress restrictions on build runners.
  • If a malicious package was installed: treat the runner/dev host as compromised. Rotate all secrets present in the environment (CI variables, .npmrc tokens, SSH keys, cloud credentials) — postinstall hooks inherit the install user's full environment.

PoeLLM:

  • Inventory AI/LLM tooling in your environment (many orgs cannot answer this today), apply egress allowlisting for model API endpoints, and monitor developer tooling for the same process-lineage anomalies described above.

Related Resources

Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.