'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
Recorded: Sept. 14, 2026, 10:09 p.m.
| Original | Summarized |
'Sandworm' Chains Cisco Flaws to Deploy Cyclops Blink Informa TechTarget|SearchSecurityCybersecurity DiveInformationWeekChannel DiveExplore our brandsAn Informa TechTarget PublicationDark Reading Resource LibraryBlack Hat NewsOmdia CybersecurityAdvertiseNewsletter Sign-UpNewsletter Sign-UpCybersecurity TopicsRelated TopicsApplication SecurityCybersecurity CareersCloud SecurityCyber RiskCyberattacks & Data BreachesCybersecurity AnalyticsCybersecurity OperationsData PrivacyEndpoint SecurityICS/OT SecurityIdentity & Access Mgmt SecurityInsider ThreatsIoTMobile SecurityPerimeterPhysical SecurityRemote WorkforceThreat IntelligenceVulnerabilities & ThreatsRecent in Cybersecurity TopicsCyberattacks & Data BreachesMaximum Severity GitLab Flaw Puts Supply Chains at RiskMaximum Severity GitLab Flaw Puts Supply Chains at RiskbyRob WrightSep 14, 20263 Min ReadSponsored ContentThe Mythos Panic Is Over. The Budget Window Isn't.The Mythos Panic Is Over. The Budget Window Isn't.Sep 14, 20265 Min ReadWorld Related TopicsDR GlobalAsia PacificEuropeLatin AmericaMiddle East & AfricaSee AllThe EdgeDR TechnologyEventsRelated TopicsUpcoming EventsPodcastsWebinarsSEE ALLResourcesRelated TopicsResource LibraryWhite PapersReportsWebinarsNewslettersPodcastsHeard It From a CISOReporters' NotebookDark Reading's 20thVideosDark Reading PollsPartner PerspectivesMeet the EditorsAdvertise With Us About UsDark Reading Resource LibraryCyberattacks & Data BreachesThreat IntelligenceVulnerabilities & ThreatsNews'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops BlinkThe notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.Jai Vijayan,Contributing WriterSeptember 14, 20264 Min ReadSource: ratpack223 via Getty ImagesA likely Russian threat actor is deploying a sophisticated malware implant capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices by chaining two vulnerabilities in Cisco's Firewall Management Center (FMC) technology.In separate reports, Sophos and Cisco identified the malware as a new version of Cyclops Blink, a modular botnet and backdoor that US and UK government agencies have previously linked to Sandworm, a threat actor with ties to Russia's Main Intelligence Directorate (GRU).Two Separate Cisco FMC VulnerabilitiesCisco described the Cyclops Blinks activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software. One of the vulnerabilities is CVE-2026-20079, a maximum severity authentication bypass vulnerability that lets an unauthenticated remote attacker run arbitrary code on affected devices and gain root access to the underlying operating system. The second vulnerability, tracked as CVE-2026-20316, is a lower severity flaw with a 5.3 CVSS score that allows a remote attacker to log in with low privileges and then use other previous FMC vulnerabilities to escalate privileges.Related:Maximum Severity GitLab Flaw Puts Supply Chains at RiskThreat actors possibly tied to Sandworm are chaining the two flaws to first download a Netcat-based reverse shell and proxy tool on vulnerable FMC systems and then use that to deploy the new Cyclops Blink variant.Cisco released hotfixes for both bugs last week and "strongly advised" organizations using the affected technology to apply them immediately, citing evidence of exploit activity in the world. The company said it would release a broader, hardened release with fixes for the two new flaws and other internally discovered vulnerabilities in FMC later this week. "Given the in the wild abuse we strongly recommend that customers apply the referenced hotfixes as soon as possible, pending the hardening release," Cisco said.Cyclops Blink is malware that first surfaced in 2022 and initially targeted WatchGuard firewalls and, later, ASUS devices. Its core functions included beaconing information about infected devices to command-and-control (C2) servers, downloading and executing malicious files, and adding new modules to expand its capabilities.The malware could persist through reboots and legitimate firmware updates, making it difficult to remove. However, the FBI led a court-authorized operation in which it accessed victims' devices, copied the Cyclops Blink malware, and then removed it.A Significant Upgrade for Cyclops BlinkThe latest variant, according to Sophos, retains many of the original features while adding several new ones. The most significant change is that the malware now runs on 64-bit x86-64 Linux systems rather than the older 32-bit PowerPC architecture used by the original version. It also uses generic Linux persistence techniques instead of modifying vendor-specific firmware.Related:Threat Actor Generates 1M Personalized Fraud Emails in 3 DaysThe new Cyclops Blink variant adds active network scanning and packet-capture capabilities and expands its data-collection functions to include password hashes, process command lines, CPU information, and configuration data. These changes potentially make Cyclops Blink compatible with a broader range of Linux-based network appliances and give attackers a more powerful platform for reconnaissance and intelligence collection, Sophos said."Generic SysV persistence in the 2026 Cyclops Blink samples removes the dependency on WatchGuard-specific firmware, while active network scanning and selective packet capture substantially expand the implant’s intelligence-collection capabilities," Sophos researchers wrote. "The discovery on Cisco FMC devices highlights the risk posed by compromised network-management infrastructure."Compromised network appliances and other edge devices can give attackers a privileged vantage point into the broader environment and allow them to observe traffic, conduct network probes, and launch additional attacks, the vendor noted.Related:Papercut AI Swarm Attack Heralds Changes for Cyber Kill ChainIn addition to the new Cyclops Blink campaign, two other groups are actively exploiting CVE-2026-20079 and CVE-2026-20316. The first cluster, which Cisco Talos is tracking as UAT 12197, is exploiting CVE-2026-20079 to plant Web shells and a Java-based command execution tool to steal credentials. The other threat cluster, UAT 11988, is exploiting CVE-2026-20316 to distribute Qilin ransomware.Sophos attributed the new Cyclops Blink campaign with high confidence to Russia-nexus actors and has moderate confidence it is associated with Sandworm, which the vendor tracks as Iron Viking. "The lower confidence in the threat group attribution reflects the absence of conclusive evidence directly linking IRON VIKING to the observed 2026 deployments," the researchers wrote.Sandworm is a Russian state-sponsored hacking group known for both espionage and destructive cyber operations. The group has been linked to some of the most consequential cyberattacks of the past decade, including attacks that disrupted Ukraine’s power grid and the NotPetya outbreak. More recently, Sandworm has expanded its use of vulnerabilities in Internet-facing infrastructure to gain access to organizations in Ukraine and elsewhere, while continuing to target critical infrastructure and other strategically important organizations.About the AuthorJai VijayanContributing WriterIllinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.See more from Jai VijayanWant more Dark Reading stories in your Google search results?Add Us NowMore InsightsIndustry ReportsThe State of Cloud Security: The Latest ChallengesHow Organizations Are Managing Incident ResponseHow Enterprises Are Developing Secure ApplicationsInside RSAC 2026: security leaders reveal the risks redefining your defense strategyEssential News & Insights from Black Hat USA 2025Access More ResearchWebinarsCybersecurity Outlook 2027Threat Exposure Analytics: Measuring and Communicating Security RiskBenchmark Scores Are a False FlagBuilding an Effective Red Team: Beyond Penetration TestingHow to Leverage Threat Intelligence Without Drowning: The Zero Noise ApproachMore WebinarsFeaturedCheck out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!Editor's ChoiceCyberattacks & Data BreachesOpenAI Agents Took Over Wiki Site Before Hugging Face AttackOpenAI Agents Took Over Wiki Site Before Hugging Face AttackbyNate NelsonSep 8, 20267 Min ReadApplication SecurityMythos Vulnerability Firehose Hits a Human BottleneckMythos Vulnerability Firehose Hits a Human BottleneckbyJai VijayanSep 9, 20264 Min ReadWant more Dark Reading stories in your Google search results?How Organizations Are Managing Incident ResponseNearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report.Download NowNovember 12, 2026 | VIRTUALWhat Every Enterprise Should Know About Securing Cloud Assets In the Age of AISave Your SpotKeep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.SubscribeDiscover MoreBlack HatOmdiaWorking With UsAbout UsMeet the EditorsAdvertiseReprintsJoin UsNewsletter Sign-UpFollow UsCopyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.Home|Cookie Policy|Privacy|Terms of UseYour Privacy Choices |
A likely Russian threat actor is deploying an advanced version of the Cyclops Blink botnet by chaining two distinct vulnerabilities within Cisco's Firewall Management Center (FMC) technology. This sophisticated malware implant is capable of harvesting credentials, scanning internal networks, and capturing live traffic from compromised devices. Cisco and Sophos identified this activity as part of one of three separate campaigns exploiting flaws in the Secure FMC software. One vulnerability, CVE-2026-20079, is a maximum severity authentication bypass flaw that allows an unauthenticated remote attacker to execute arbitrary code and gain root access to the underlying operating system. The second flaw, CVE-2026-20316, is a lower severity vulnerability with a 5.3 CVSS score that permits a remote attacker to log in with minimal privileges and subsequently escalate those privileges by exploiting previously identified FMC vulnerabilities. Threat actors utilize these two flaws to first establish a foothold by downloading a Netcat-based reverse shell and proxy tool on the vulnerable FMC systems, which then enables the deployment of the new Cyclops Blink variant. Cisco promptly released hotfixes for both bugs and strongly recommended that organizations using the affected technology apply them immediately pending a broader, hardened release. The Cyclops Blink malware initially emerged in 2022, targeting platforms like WatchGuard firewalls and ASUS devices. Its core functionality involved beaconing information to command-and-control servers, downloading and executing malicious files, and adding modules to enhance its overall capabilities, with the malware designed to persist across reboots and legitimate firmware updates. Sophos noted that the latest variant introduces several significant upgrades. The most notable change is that it now operates on 64-bit x86-64 Linux systems rather than the older 32-bit PowerPC architecture of the original version, employing generic Linux persistence techniques instead of relying on vendor-specific firmware modifications. Furthermore, this upgraded iteration enhances the malware's intelligence-collection profile by adding active network scanning and packet capture functionalities, expanding data collection to include password hashes, process command lines, CPU information, and configuration data. This evolution potentially broadens the malware's compatibility with a wider array of Linux-based network appliances, providing attackers with a more potent platform for reconnaissance and intelligence gathering. Sophos researchers indicated that the persistence mechanism in the 2026 Cyclops Blink samples utilizes generic SysV persistence, effectively removing dependency on WatchGuard-specific firmware. The enhanced capabilities, specifically active network scanning and selective packet capture, substantially increase the implant's capacity for intelligence collection. The discovery on Cisco FMC devices highlights the critical risk posed by compromised network-management infrastructure, as these compromised appliances offer attackers a privileged vantage point to observe traffic, probe the network, and launch further attacks. Beyond the Cyclops Blink campaign, other threat clusters are actively exploiting CVE-2026-20079 and CVE-2026-20316. One cluster, tracked by Cisco Talos as UAT 12197, leverages CVE-2026-20079 to plant web shells and a Java-based command execution tool designed for credential theft. Another cluster, UAT 11988, exploits CVE-2026-20316 to distribute Qilin ransomware. Sophos attributed the new Cyclops Blink campaign with high confidence to Russia-nexus actors, assigning moderate confidence to its association with Sandworm, which the vendor tracks as Iron Viking. Sandworm is recognized as a Russian state-sponsored hacking group known for both espionage and destructive cyber operations, having been implicated in significant attacks such as disrupting Ukraine’s power grid and the NotPetya outbreak. The involvement of Sandworm reflects the group's expanded use of vulnerabilities in internet-facing infrastructure to gain access to organizations in Ukraine and elsewhere, continuing its focus on critical infrastructure and strategically important entities. |