TF-MAL-elf.cyclops_blink
📛 Threat Title
Malware family: CyclopsBlink
Description
ThreatFox malware family `elf.cyclops_blink`. Printable name: CyclopsBlink.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Cyclops Blink Cyclops Blink is a modular malware that has been used in widespread campaigns by Sandworm Team since at least 2019 to target Small/Home Office (SOHO) network devices, including WatchGuard and Asus.
-
web:cds.thalesgroup.com
In March, the Federal Bureau of Investigation (FBI) took down a large-scale botnet belonging to a Russian state-sponsored threat actor known as Sandworm. According to a TechCrunch report, Sandworm infected thousands of endpoints with Cyclops Blink malware , successor to the now-defunct VPNFilter. Cyclops Blink allows Sandworm to conduct cyber espionage, launch distributed denial of service ...
-
web:en.wikipedia.org
Cyclops Blink is malicious Linux ELF executable, compiled for the 32-bit PowerPC (big endian) architecture. It targeted routers and firewall devices from WatchGuard and ASUS and adds them to a botnet for command and control (C&C).
-
web:malpedia.caad.fkie.fraunhofer.de
According to CISA, Cyclops Blink appears to be a replacement framework for the VPNFilter malware exposed in 2018, and which exploited network devices, primarily small office/home office (SOHO) routers and network attached storage (NAS) devices. Cyclops Blink has been deployed since at least June 2019, fourteen months after VPNFilter was disrupted. In common with VPNFilter, Cyclops Blink ...
-
web:socprime.com
The threat can persist the device reboot, which makes its mitigation a sophisticated task. The inquiry by FBI, CISA, NSA, and UK NCSC states that Cyclops Blink impacts only WatchGuard network devices. Presumably, the malware developers reverse-engineered the WatchGuard Firebox firmware update mechanism to check for possible flaws and exploit them.
-
web:threatintelligence.garden.handsomezebra.com
Cyclops Blink Description (CISA) The NCSC, CISA, the FBI, and NSA, along with industry partners, have now identified a large-scale modular malware framework (T1129) which is targeting network devices.
-
web:thrive.trellix.com
The malware targets ASUS routers around the world and has also attacked WatchGuard Firebox devices. Cyclops Blink is written in the C programming language, encrypts data using OpenSSL functions, and can execute multiple commands on the infected system.
-
web:www.cisa.gov
This advisory summarizes the VPNFilter malware it replaces, and provides more detail on Cyclops Blink, as well as the associated tactics, techniques and procedures (TTPs) used by Sandworm. An NCSC malware analysis report on Cyclops Blink is also available. It also provides mitigation measures to help organizations defend against malware .
-
web:www.ncsc.gov.uk
The NCSC has published a malware analysis report on Cyclops Blink which provides more detail about the malware . Post exploitation Post exploitation, Cyclops Blink is generally deployed as part of a firmware 'update' (T1542.001). This achieves persistence when the device is rebooted and makes remediation harder.
-
web:www.watchguard.com
Please note that the remediation steps are only necessary if you have an infected appliance; however, the future protection steps are applicable to all customers. The recommended 4-Step Cyclops Blink Diagnosis and Remediation Plan includes information to help customers select the detection tool most appropriate for their individual needs.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.