HomeCyber BalkansSandworm-Linked Cyclops Blink Reemerges with Network Scanning and Packet-Sniffing Features

Sandworm-Linked Cyclops Blink Reemerges with Network Scanning and Packet-Sniffing Features

Published on

spot_img

Emerging Threat: New Cyclops Blink Variant Targets Cisco Secure Firewall Management Center

A recent development in cybersecurity has uncovered a newly identified variant of Cyclops Blink malware lurking on compromised Cisco Secure Firewall Management Center (FMC) appliances. The modern iteration, boasting advanced capabilities for internal-network scanning and programmable packet-sniffing, signifies a worrying evolution of this already sophisticated modular implant.

Cybersecurity experts have assessed the resurgence of this malware with high confidence that it has ties to Russian cyber-operations, with moderate indications linking it to a group known as IRON VIKING, also referred to as Sandworm and Seashell Blizzard. This attribution aligns with broader concerns regarding state-sponsored cyber threats emanating from Russia.

Cisco Talos, the threat intelligence and research arm of Cisco, made public disclosures about the FMC exploitation activity on September 9. This announcement serves as a critical reminder of the risks posed by vulnerabilities within network management systems. The attacks exploit two specific vulnerabilities, identified as CVE-2026-20079 and CVE-2026-20316. These weaknesses granted attackers the ability to deploy reverse shells and proxy tools, facilitating unauthorized data access and the installation of Cyclops Blink onto vulnerable devices.

CVE-2026-20079 specifically is an authentication-bypass vulnerability that allows unauthenticated remote attackers to execute scripts and gain root access on affected FMC devices. Meanwhile, CVE-2026-20316 enables attackers to log in using low-privileged accounts, thereby providing a pathway for further exploitation.

The emergence of this fresh variant marks a notable evolution for Cyclops Blink—a malware family publicly attributed to the GRU-linked Sandworm operation as of 2022. Previous iterations primarily targeted WatchGuard Firebox devices operating on 32-bit PowerPC Linux systems. The current manifestation, however, has shifted to a 64-bit x86-64 ELF implant that is more adaptable, displaying a modular framework that enhances its functionality across a broader spectrum of Linux-based network-management systems, VPNs, routers, and security appliances.

The current version operates through a component dubbed the "timezone_check" implant, which functions under a parent controller. This parent controller disguises itself as [kworker/0:1], mimicking legitimate Linux kernel activity in system process listings to avoid detection. It coordinates a suite of dedicated worker modules, synchronizing configurations, encrypting collected output, and communicating over TLS-protected command-and-control (C2) channels.

In a bid to ensure its persistence, the malware manipulates local firewall policies by adding specific iptables rules for TCP ports 43856 and 49172, which are critical for its C2 communications. Additionally, cybersecurity researchers at Sophos Counter Threat Unit (CTU) undertook an analysis of the 64-bit Linux executable in August 2026, revealing its elaborate capabilities in data exfiltration.

The Cyclops Blink variant has a hard-coded C2 address—89[.]34[.]96[.]56—and notably operates without adhering to conventional certificate validations during TLS sessions. The malware uses a custom protocol for data exchange, diverging from standard HTTP methodologies. Its C2 configuration is adaptable; operators have the ability to remotely adjust various parameters such as changing C2 addresses, forcing beacons, modifying connection timings, and loading additional worker modules.

Among the most significant upgrades are newly introduced modules for network discovery and selective traffic collection. This includes Module 0x11, which identifies locally connected IPv4 networks while scanning attacker-defined ranges or specific ports associated with various administrative and networking services. This module utilizes crafted Ethernet frames to discern open ports and can conduct TCP handshakes, seamlessly pulling in HTTP responses or performing TLS probing.

Taking advantage of its privileged position within the FMC, this enhanced scanning ability jeopardizes internal management systems and services that would typically remain inaccessible from external threats.

Module 0x12 offers targeted packet capture capabilities, using a raw socket to collect visible Ethernet frames and parse IPv4 TCP and UDP payloads for further scrutiny. The granularity of this functionality allows operators to filter packets based on criteria like duration, protocol, and address, which can lead to the retrieval of sensitive information including credentials and access tokens.

The malware is designed to maintain its persistence by self-copying into system directories such as /lib/tz/timezone_check and establishing startup links that disguise its operation as benign, leveraging themes associated with time zone configurations. Such subtlety suggests that its installation likely requires root-level permissions, enhancing its ability to evade detection.

Considering these developments, organizations must prioritize securing their FMC and similar network-edge management systems, recognizing their potential as high-value targets. Cisco noted the exploitation tactics through UAT-11823, which involved chaining the identified FMC vulnerabilities before deploying a Netcat reverse shell, proxy tools, and the Cyclops Blink variant.

In response to these alarming findings, companies are urged to promptly apply Cisco’s hotfixes, meticulously inspect their FMC devices for suspicious SysV services, and review outbound TLS sessions on the relevant ports. Implementing robust monitoring practices to detect unusual internal probes and raw-socket scanning behavior is imperative to mitigate the risks posed by this malware resurgence.

The Cyclops Blink incident serves as a stark reminder that compromised management-plane appliances can evolve into potent internal reconnaissance platforms, thereby posing heightened risks for broader state-sponsored cyber operations linked to groups like Sandworm.

Source link

Latest articles

Hackers Take Advantage of Critical Vulnerability in GitLab

Urgent Appeal for GitLab Users to Address Severe Vulnerability Amid Exploitation Reports GitLab users are...

Insights from the 3M ChatGPT Case on AI Governance

Reflecting on AI Decision-Making a Year Later: Key Considerations for Organizations In the realm of...

How to Advance from Security Professional to Security Leader

Strategies for Aspiring CISOs: Building Trust and Leadership Effective leadership in the dynamic field of...

Casbaneiro Banking Trojan Employs Distributed C2 Servers to Avoid Detection and Target Banking Customers

Casbaneiro Banking Trojan Campaign Targets Latin American Users A sophisticated campaign utilizing the Casbaneiro banking...

More like this

Hackers Take Advantage of Critical Vulnerability in GitLab

Urgent Appeal for GitLab Users to Address Severe Vulnerability Amid Exploitation Reports GitLab users are...

Insights from the 3M ChatGPT Case on AI Governance

Reflecting on AI Decision-Making a Year Later: Key Considerations for Organizations In the realm of...

How to Advance from Security Professional to Security Leader

Strategies for Aspiring CISOs: Building Trust and Leadership Effective leadership in the dynamic field of...