UAT-11823 is an advanced persistent threat cluster assessed with high confidence to overlap in tooling with Sandworm, the Russian military-linked threat actor associated with Russia's GRU. The cluster targeted Cisco Secure Firewall Management Center appliances by chaining CVE-2026-20079 and CVE-2026-20316 to obtain privileged access. It abused legitimate FMC functionality to execute a trojanized package as root and establish a Netcat-based reverse shell. UAT-11823 collected and archived managed-device configuration data for exfiltration, then deployed a modular Cyclops Blink variant. The deployed backdoor supported init.d-based persistence, DNS-over-HTTPS command-and-control resolution, file transfer, credential harvesting, remote command execution, network discovery, and packet sniffing. Cyclops Blink has independently been publicly attributed by the United States and United Kingdom to Sandworm.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2026-20079 has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts as root on vulnerable FMC devices. Talos confirmed UAT-11823 exploited both vulnerabilities, while UAT-12197 exploited CVE-2026-20079 to deploy a JSP web shell and steal credentials.
CVE-2026-20316 allows attackers to log in to FMC using static credentials for a low-privileged account. UAT-11988 used the static credentials to access an FMC device before deploying Qilin ransomware, and UAT-11823 exploited the flaw alongside CVE-2026-20079 and deployed Cyclops Blink.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An advanced persistent threat cluster with tooling overlap to Sandworm that exploited Cisco FMC vulnerabilities, established root-level reverse-shell access, collected configuration data for exfiltration, and deployed a Cyclops Blink variant for persistence, credential theft, and network sniffing.
A Russian military-linked/Sandworm-overlapping cluster that chained both FMC flaws, trojanized a license file, established a Netcat reverse shell, exfiltrated configurations, and deployed Cyclops Blink on compromised FMC devices.
A Russian military-linked cluster that chained both Cisco FMC flaws, replaced a legitimate license file with a malicious Makeself package, established a Netcat reverse shell, exfiltrated configurations, and deployed Cyclops Blink.
Conducted intrusions against Cisco FMC devices using CVE-2026-20079 and CVE-2026-20316 or static credentials; deployed Netcat reverse shells, configuration-harvesting scripts, and a Cyclops Blink implant. Its tooling overlaps with Sandworm.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.