Cyclops Blink is a modular Linux malware framework and botnet associated with Sandworm, a threat actor widely attributed to Russia’s GRU. Active since at least June 2019, it is broadly regarded as the successor to VPNFilter and was used to compromise internet-facing perimeter network devices, particularly WatchGuard Firebox appliances and multiple ASUS router models. Infected devices were incorporated into a two-tier botnet architecture that included command-and-control nodes and downstream bots, enabling Sandworm to manage thousands of compromised devices worldwide while obscuring follow-on operations.
Cyclops Blink is designed for persistence on embedded network devices and can survive through firmware-related mechanisms. It supports remote command-and-control, device and network discovery, download of additional payloads, and upload of collected data. Reported functionality includes gathering device information, enumerating network interface names via Linux APIs, retrieving and transferring files, and communicating over HTTP and HTTPS. Its command traffic has been described as additionally protected with AES-256-CBC under TLS using OpenSSL and RSA-wrapped session material. The malware’s modular design allows it to be upgraded for additional capabilities and adapted to new device types.
Because it targets firewalls and routers commonly deployed at network perimeters, Cyclops Blink can provide attackers with durable access into victim environments and a platform for subsequent malicious activity against internal systems. Public reporting has noted its potential utility for remote access, malware deployment, distributed denial-of-service operations, and broader post-compromise activity. Government and industry reporting tied the malware to Russian operations during the period surrounding the invasion of Ukraine, and U.S. authorities conducted a court-authorized disruption in 2022 that removed Cyclops Blink from identified command-and-control devices and severed Sandworm’s control over many infected bots. Device owners still needed to remediate and patch affected hardware because disruption of the botnet infrastructure did not itself clean all compromised victim devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2022-26318 appears to be related to Cyclops Blinked, Sandworm’s VPNFilter 2.0 which was recently unmasked by CISA, NSA, NCSC UK, and the FBI. | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On Feb. 23, the United Kingdom’s National Cyber Security Centre, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, the FBI and the National Security Agency released an advisory identifying the Cyclops Blink malware, which targets network devices manufactured by WatchGuard Technologies Inc. (WatchGuard) and ASUSTek Computer Inc. (ASUS).
The Splunk Threat Research Team has developed specific analytics to detect this type of malicious code, including Cyclops Blink, and AcidRain.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
RedCurl mimicked legitimate file names and scheduled tasks, e.g. MicrosoftCurrentupdatesCheck and MdMMaintenenceTask to mask malicious files and scheduled tasks.
Akira has used legitimate names and locations for files to evade defenses.
Cyclops Blink can rename its running process to [kworker:0/1] to masquerade as a Linux kernel thread.
J-magic can rename itself as "[nfsiod 0]" to masquerade as the local Network File System (NFS) asynchronous I/O server.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
The operation copied and removed malware from vulnerable internet-connected firewall devices that Sandworm used for command and control (C2) of the underlying botnet.
higher-end threat actors will compromise opportunistic, seemingly random endpoints wherever they can be found to build out proxy networks of hosts to channel and obfuscate subsequent operations.
246 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet referenced as part of prior FBI disruption operations against router-focused threats.
Sandworm malware used to establish persistent access and botnet capability on network devices; described as replacing VPNFilter.
Cyclops Blink is a modular malware platform used to build botnets by compromising network devices such as routers and firewalls. It is known for targeting WatchGuard Firebox and ASUS routers, enabling remote control and persistence for threat actors.
Mentioned as a comparative example of compromised-device proxy network activity involving SOHO/network appliances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.