Cyclops Blink is a modular Linux backdoor and botnet implant associated with Sandworm, a Russian state-sponsored threat actor. First identified on WatchGuard and ASUS perimeter devices, later variants have targeted x86-64 Linux-based Cisco Secure Firewall Management Center appliances. The implant provides persistent remote access through a controller-and-worker architecture, uses outbound TLS-protected custom command-and-control communications, and can alter its beacon configuration and command-and-control server list at runtime. Linux variants establish persistence through System V init services and masquerade their controller as a legitimate-looking Linux worker process.
Cyclops Blink performs extensive host and network reconnaissance, including collection of system, account, process, filesystem, network-interface, routing-adjacent, and resolver information. Where privileges permit, it can collect password hashes. It can upload accessible files, download and execute additional payloads, and load Linux executable code directly into memory. Its network modules enumerate connected IPv4 networks, scan selected internal ports, probe services including web and TLS endpoints, and capture raw Ethernet traffic using configurable address, port, time, and content filters. This selective packet collection can obtain attacker-specified credentials, session material, authentication tokens, administrative commands, and sensitive application requests visible to the compromised appliance.
The malware has been used in compromises of network-edge and firewall-management infrastructure, including activity involving exploitation of Cisco Secure Firewall Management Center vulnerabilities. Such deployments give operators a durable position from which to collect managed-device configurations, observe privileged management networks, conduct internal discovery, and support follow-on operations. Cyclops Blink has been described as a successor framework to Sandworm's VPNFilter botnet.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cisco Secure Firewall Management Center (FMC) contains an unauthenticated authentication-bypass vulnerability that can result in root access to the underlying appliance. Cisco confirmed active exploitation beginning in August 2026. | UAT-11823 — Linked to Sandworm (Russian state-sponsored APT); deploys the Cyclops Blink implant and harvests managed-firewall configurations.
CVE-2026-20316 (CVSS 5.3) : Permet à un attaquant distant de se connecter avec un compte à faibles privilèges ; utilisable en chaîne avec d’autres vulnérabilités pour élever les privilèges.
CVE-2022-26318 appears to be related to Cyclops Blinked, Sandworm’s VPNFilter 2.0 which was recently unmasked by CISA, NSA, NCSC UK, and the FBI. | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cyclops Blink was found on compromised Cisco Firewall Management Center devices, where it can maintain remote access, inspect traffic, map systems behind the network edge, scan internal networks, and capture selected raw Ethernet traffic.
UAT-11823 — Linked to Sandworm (Russian state-sponsored APT); deploys the Cyclops Blink implant and harvests managed-firewall configurations.
The Splunk Threat Research Team has developed specific analytics to detect this type of malicious code, including Cyclops Blink, and AcidRain.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Module 0x50 establishes persistence by relocating the implant to a system directory and registering the relocated executable as a SysV init service.
Module 0x50 establishes persistence by relocating the implant to a system directory and registering the relocated executable as a SysV init service.
It also makes its controller resemble an ordinary Linux worker process, an attempt to blend into routine process listings and reduce the chance of casual discovery.
If the implant instance has sufficient privileges ... the module may also access /etc/shadow, potentially exposing password hashes for offline analysis.
A separate capture module listens for raw Ethernet traffic visible to the host and retains packets matching attacker-defined terms.
The implant profiles the host and its nearby network, collecting operating-system, account, process, storage, interface, and resolver details.
A separate capture module listens for raw Ethernet traffic visible to the host and retains packets matching attacker-defined terms.
The internal scanner identifies locally connected IPv4 networks and tests either operator-selected ports or a built-in list linked to administration, file sharing, messaging, directory services, web applications, network monitoring, VPNs, and virtualization.
The implant profiles the host and its nearby network, collecting operating-system, account, process, storage, interface, and resolver details.
Its command-and-control channel uses outbound TLS connections and a custom protocol instead of ordinary web traffic.
This module uses an embedded DNS-over-HTTPS resolver ... establishes a TLS connection directly to the Google public DNS at 8.8.8.8:443 [and] submits a binary DNS query via an HTTP POST request to /dns-query.
Its command-and-control channel uses outbound TLS connections and a custom protocol instead of ordinary web traffic.
254 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
66 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular Linux-based implant/backdoor deployed on compromised Cisco Firewall Management Center appliances. It persists through SysV init services, disguises its controller as kworker01, profiles hosts and internal networks, can retrieve password hashes where permitted, scans internal services, captures attacker-filtered Ethernet traffic, exfiltrates files, and downloads or executes follow-on payloads. Its C2 uses outbound TLS and configurable beacon timing.
A modular Linux implant/backdoor for network appliances. The analyzed x86-64 variant persists through SysV init services, profiles hosts and nearby networks, can retrieve password hashes, exfiltrate files, download and execute additional tools, conduct internal port and web/TLS scanning, and selectively sniff network packets. It communicates with command-and-control infrastructure over outbound TLS using a custom protocol.
Modular ELF malware used to maintain persistent access, resolve infrastructure through DNS over HTTPS, and sniff network packets on compromised FMC systems.
A modular ELF implant previously attributed to the Russian state-sponsored Sandworm group. A variant was deployed following compromise of Cisco Secure FMC instances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.