The U.S. Department of Justice and FBI said they disrupted Cyclops Blink, a botnet attributed to the Russian state-backed Sandworm group, before it was used in follow-on attacks. Authorities said the malware had been active since at least 2019, compromising WatchGuard Firebox firewall appliances and multiple ASUS router models, using firmware-level persistence and remote-access capabilities to turn infected devices into command-and-control infrastructure. In a court-authorized operation, the FBI removed malware from identified WatchGuard devices acting as C2 servers and worked with foreign law enforcement and service providers to notify affected owners.
Officials warned that thousands of network devices were involved and that previously compromised systems could remain exposed until administrators apply vendor remediation and update to the latest Fireware OS guidance from WatchGuard. The disruption drew added attention because Sandworm has been tied to some of the most consequential cyber operations against Ukraine, including the 2015 power-grid attack linked to BlackEnergy and KillDisk, which caused civilian outages and demonstrated the group’s history of targeting critical infrastructure.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
U.S. government officials announced on April 6, 2022 that they had disrupted the GRU-linked Cyclops Blink botnet before it could be used in attacks. The botnet was attributed to Sandworm, and WatchGuard published remediation guidance for affected Firebox appliances.
On March 18, the U.S. Department of Justice obtained initial court authorization for an operation against the Cyclops Blink botnet. The operation targeted identified WatchGuard devices acting as command-and-control servers.
U.S. officials said Sandworm had used Cyclops Blink since at least June 2019 to build a botnet from compromised WatchGuard Firebox appliances and multiple ASUS router models. The malware established persistence through firmware updates and enabled remote access to victim networks.
FireEye reported on January 8, 2016 that SANS ICS assessed with high confidence that cyberattacks directly caused the Ukrainian power outages, and iSIGHT Partners attributed the incident to Sandworm Team. The reporting linked the attack primarily to BlackEnergy 3 and related KillDisk malware.
On December 23, 2015, Sandworm operators used stolen access to manually open breakers at more than 30 substations, causing a major blackout in parts of Kyiv and western Ukraine. The operation also involved KillDisk and telecom disruption, and reportedly affected about 1.4 million people for roughly six hours.
FireEye says BlackEnergy 3 reemerged in Ukraine in early 2015 after Sandworm reduced visible activity following its 2014 exposure. iSIGHT also observed increased intrusion activity using BlackEnergy 3 throughout 2015.
iSIGHT Partners publicly reported on Sandworm Team activity in October 2014, including use of zero-day exploit CVE-2014-4114. The campaign targeted Ukrainian government officials as well as EU and NATO members.
Following the court-authorized action, the FBI removed Cyclops Blink malware from identified compromised WatchGuard devices and notified affected owners in the United States and abroad with help from foreign partners and service providers. Officials said the botnet involved thousands of infected network devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
10 references tracked. Mallory keeps watching after this page renders.
techsearch.watchguard.com
Open sourcectfiot.com
Open sourcesplunk.com
Open sourcejustice.gov
Open sourcegithub.com
Open sourcefireeye.com
Open sourcencsc.gov.uk
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.