Cyclops Blink is a modular Linux backdoor associated with the Russian state-sponsored Sandworm threat group and its operations against network-edge infrastructure. Earlier documented variants targeted PowerPC-based WatchGuard appliances. An x86-64 ELF variant identified on compromised Cisco Secure Firewall Management Center devices in August 2026 provides persistent remote access and surveillance of internal management networks.
The implant uses a parent controller and separate worker modules for host reconnaissance, file administration, network scanning, packet capture, and persistence. It collects operating-system, account, process, storage, and network information and can retrieve password hashes when privileges permit. Operators can upload and download files, execute arbitrary commands and additional payloads, and load downloaded Linux code directly into memory. Its scanner discovers internal IPv4 services and collects service responses, while its packet-capture module selectively retains raw Ethernet traffic using operator-defined filters, potentially exposing credentials, authentication tokens, and sensitive application traffic.
The x86-64 variant persists through SysV startup services and disguises its controller as a Linux kernel worker process. Command-and-control uses outbound TLS connections with a custom application protocol and additional application-layer cryptographic protection. Operators can change controller addresses, beacon intervals, and worker modules at runtime; the implant also supports DNS-over-HTTPS resolution.
The intrusion cluster UAT-11823, whose tooling overlaps with Sandworm, deployed Cyclops Blink after exploiting Cisco FMC vulnerabilities CVE-2026-20079 and CVE-2026-20316. These deployments place the implant on privileged network-management infrastructure, supporting intelligence collection and follow-on targeting of internal systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cisco Secure Firewall Management Center (FMC) contains an unauthenticated authentication-bypass vulnerability that can result in root access to the underlying appliance. Cisco confirmed active exploitation beginning in August 2026. | UAT-11823 — Linked to Sandworm (Russian state-sponsored APT); deploys the Cyclops Blink implant and harvests managed-firewall configurations.
CVE-2026-20316 (CVSS 5.3) : Permet à un attaquant distant de se connecter avec un compte à faibles privilèges ; utilisable en chaîne avec d’autres vulnérabilités pour élever les privilèges.
CVE-2022-26318 appears to be related to Cyclops Blinked, Sandworm’s VPNFilter 2.0 which was recently unmasked by CISA, NSA, NCSC UK, and the FBI. | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm made the headlines this week with an alert announcing Cyclops Blink has replaced the VPNFilter malware.
UAT-11823 — Linked to Sandworm (Russian state-sponsored APT); deploys the Cyclops Blink implant and harvests managed-firewall configurations.
The Splunk Threat Research Team has developed specific analytics to detect this type of malicious code, including Cyclops Blink, and AcidRain.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The implant profiles the host and its nearby network, collecting operating-system, account, process, storage, interface, and resolver details.
A separate capture module listens for raw Ethernet traffic visible to the host and retains packets matching attacker-defined terms.
The implant profiles the host and its nearby network, collecting operating-system, account, process, storage, interface, and resolver details.
258 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
68 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular Linux-based implant/backdoor deployed on compromised Cisco Firewall Management Center appliances. It persists through SysV init services, disguises its controller as kworker01, profiles hosts and internal networks, can retrieve password hashes where permitted, scans internal services, captures attacker-filtered Ethernet traffic, exfiltrates files, and downloads or executes follow-on payloads. Its C2 uses outbound TLS and configurable beacon timing.
A modular Linux implant/backdoor for network appliances. The analyzed x86-64 variant persists through SysV init services, profiles hosts and nearby networks, can retrieve password hashes, exfiltrate files, download and execute additional tools, conduct internal port and web/TLS scanning, and selectively sniff network packets. It communicates with command-and-control infrastructure over outbound TLS using a custom protocol.
Modular ELF malware used to maintain persistent access, resolve infrastructure through DNS over HTTPS, and sniff network packets on compromised FMC systems.
A modular ELF implant previously attributed to the Russian state-sponsored Sandworm group. A variant was deployed following compromise of Cisco Secure FMC instances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.