CyclopsBlink is an Internet-of-Things malware/botnet associated with the Russian Sandworm group (also referred to in the content as unit 74455, VoodooBear, and BlackEnergy). It has been described as a replacement for Sandworm's VPNFilter botnet. The malware targets network devices including routers and has been reported on WatchGuard Firebox devices and ASUS routers. Routers left with standard settings that allow external access are described as particularly vulnerable. Once installed, CyclopsBlink causes the infected router to communicate with computers operated by unit 74455 as part of a global botnet of compromised devices. The content states this infrastructure has been used for sabotage, espionage, and the spread of fake news. Reporting cited in the content says private individuals and small and medium-sized businesses in the Netherlands were affected, with Dutch military intelligence (MIVD) identifying compromised routers and warning owners; Dutch IP addresses were assessed to have been selected randomly, and no Dutch government or critical infrastructure systems were reported affected in that case. The content also states that Sandworm deployed CyclopsBlink against Ukrainian ICS/OT devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The MIVD findings follow a warning by British and American intelligence agencies about a new type of malware called CyclopsBlink, the paper said. Routers with standard settings allowing outside access are particularly vulnerable. Once the malware is installed, the router communicates with the 74455 unit computers in a network which is used for sabotage, spying and the spread of fake news.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CyclopsBlink is a modular malware platform used to build botnets by compromising network devices such as WatchGuard Firebox appliances and ASUS routers. It is known for persistent access and control over infected devices, often used for large-scale attacks and infrastructure compromise.
The content references CyclopsBlink as the malware for which attack simulation datasets were generated in an attack range environment.
Router-focused malware that infects vulnerable devices and connects them to a command-and-control network used for sabotage, espionage, and information operations.
IoT malware and botnet used to target ICS/OT devices, attributed to the Sandworm group as a replacement for VPNfilter.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.