UAT-11823 is an advanced persistent threat cluster assessed with high confidence to have tooling overlap with Sandworm, the Russian military-linked threat actor. The cluster targeted Cisco Secure Firewall Management Center appliances, exploiting CVE-2026-20079 and CVE-2026-20316 to obtain access and execute malicious packages with elevated privileges. It established Netcat-based reverse shells, harvested and archived managed-device configuration data for exfiltration, and deployed a modular Cyclops Blink variant. The observed Cyclops Blink variant supports persistence, DNS-over-HTTPS resolution, file operations, credential harvesting, arbitrary command execution, network scanning, and packet sniffing. UAT-11823 activity is consistent with espionage-oriented collection and persistent access operations against network-management infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Cisco Secure Firewall Management Center (FMC) contains an unauthenticated authentication-bypass vulnerability that can result in root access to the underlying appliance. Cisco confirmed active exploitation beginning in August 2026.
CVE-2026-20316 (CVSS 5.3) : Permet à un attaquant distant de se connecter avec un compte à faibles privilèges ; utilisable en chaîne avec d’autres vulnérabilités pour élever les privilèges.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses exploitation of CVE-2026-20079 or static credentials to access Cisco FMC systems, establish Netcat reverse shells, collect device configurations, and install Cyclops Blink for persistence, DNS-over-HTTPS resolution, and packet sniffing.
Post-compromise activity cluster linked to state-sponsored activity that deployed remote-shell and configuration-collection tooling, including a Cyclops Blink variant, against Cisco Secure FMC instances.
A threat cluster exploiting two Cisco FMC vulnerabilities to establish a reverse shell, harvest managed-device configurations, and deploy a Cyclops Blink variant.
A Cisco FMC intrusion cluster linked to Sandworm that exploits CVE-2026-20079, deploys Cyclops Blink, and steals managed-firewall configurations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.