Sandworm Linked to Cisco Vulnerability Exploitation and Cyclops Blink Deployment
Share
Threat actors likely tied to the Russian state-sponsored group Sandworm are exploiting vulnerabilities in Cisco Firewall Management Center (FMC) software to deploy an upgraded version of the Cyclops Blink botnet.
The campaign involves chaining two specific flaws in Cisco’s Secure FMC software to gain control over network management infrastructure. The first is CVE-2026-20079, a maximum severity authentication bypass vulnerability that allows unauthenticated remote attackers to run arbitrary code and gain root access. The second is CVE-2026-20316, a lower severity flaw that facilitates privilege escalation.
Attackers use these vulnerabilities to download a Netcat-based reverse shell and proxy tool, which provides the foundation for deploying the Cyclops Blink malware variant.
Upgraded Malware Capabilities
Sophos researchers identified the new variant as a significant evolution of the original Cyclops Blink, which first appeared in 2022. The updated malware has transitioned from the older 32-bit PowerPC architecture to 64-bit x86-64 Linux systems.
The new version also employs generic Linux persistence techniques, such as SysV persistence, rather than modifying vendor-specific firmware. This change makes the malware compatible with a wider range of Linux-based network appliances. Additionally, the implant has expanded its intelligence-gathering capabilities to include active network scanning, selective packet capture, and the collection of password hashes, process command lines, and configuration data.
Security researchers at Sophos noted that the discovery on Cisco FMC devices highlights the heightened risk posed when network-management infrastructure is compromised, as it provides attackers with a privileged vantage point to observe traffic and probe the broader environment.
Wider Exploitation of Cisco Flaws
Cisco Talos is tracking two other distinct threat clusters exploiting these same vulnerabilities for different purposes. One cluster, identified as UAT 12197, is using the authentication bypass flaw to plant web shells and Java-based command execution tools to steal credentials. Another cluster, UAT 11988, is leveraging the privilege escalation flaw to distribute Qilin ransomware.
Mitigation and Vendor Response
Cisco has released hotfixes for both vulnerabilities and has strongly advised organisations using the affected technology to apply them immediately. The company stated it would also release a broader, hardened software release containing fixes for these flaws and other internally discovered vulnerabilities later this week.




Leave a Reply