s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.cyclops_blink

📛 Threat Title

Malware family: CyclopsBlink

Category: CyclopsBlink First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.cyclops_blink`. Printable name: CyclopsBlink.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    Cyclops Blink Cyclops Blink is a modular malware that has been used in widespread campaigns by Sandworm Team since at least 2019 to target Small/Home Office (SOHO) network devices, including WatchGuard and Asus.

  • web:cds.thalesgroup.com

    In March, the Federal Bureau of Investigation (FBI) took down a large-scale botnet belonging to a Russian state-sponsored threat actor known as Sandworm. According to a TechCrunch report, Sandworm infected thousands of endpoints with Cyclops Blink malware , successor to the now-defunct VPNFilter. Cyclops Blink allows Sandworm to conduct cyber espionage, launch distributed denial of service ...

  • web:en.wikipedia.org

    Cyclops Blink is malicious Linux ELF executable, compiled for the 32-bit PowerPC (big endian) architecture. It targeted routers and firewall devices from WatchGuard and ASUS and adds them to a botnet for command and control (C&C).

  • web:malpedia.caad.fkie.fraunhofer.de

    According to CISA, Cyclops Blink appears to be a replacement framework for the VPNFilter malware exposed in 2018, and which exploited network devices, primarily small office/home office (SOHO) routers and network attached storage (NAS) devices. Cyclops Blink has been deployed since at least June 2019, fourteen months after VPNFilter was disrupted. In common with VPNFilter, Cyclops Blink ...

  • web:socprime.com

    The threat can persist the device reboot, which makes its mitigation a sophisticated task. The inquiry by FBI, CISA, NSA, and UK NCSC states that Cyclops Blink impacts only WatchGuard network devices. Presumably, the malware developers reverse-engineered the WatchGuard Firebox firmware update mechanism to check for possible flaws and exploit them.

  • web:threatintelligence.garden.handsomezebra.com

    Cyclops Blink Description (CISA) The NCSC, CISA, the FBI, and NSA, along with industry partners, have now identified a large-scale modular malware framework (T1129) which is targeting network devices.

  • web:thrive.trellix.com

    The malware targets ASUS routers around the world and has also attacked WatchGuard Firebox devices. Cyclops Blink is written in the C programming language, encrypts data using OpenSSL functions, and can execute multiple commands on the infected system.

  • web:www.cisa.gov

    This advisory summarizes the VPNFilter malware it replaces, and provides more detail on Cyclops Blink, as well as the associated tactics, techniques and procedures (TTPs) used by Sandworm. An NCSC malware analysis report on Cyclops Blink is also available. It also provides mitigation measures to help organizations defend against malware .

  • web:www.ncsc.gov.uk

    The NCSC has published a malware analysis report on Cyclops Blink which provides more detail about the malware . Post exploitation Post exploitation, Cyclops Blink is generally deployed as part of a firmware 'update' (T1542.001). This achieves persistence when the device is rebooted and makes remediation harder.

  • web:www.watchguard.com

    Please note that the remediation steps are only necessary if you have an infected appliance; however, the future protection steps are applicable to all customers. The recommended 4-Step Cyclops Blink Diagnosis and Remediation Plan includes information to help customers select the detection tool most appropriate for their individual needs.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.