The Russian threat group Sandworm has leveraged two critical Cisco FMC vulnerabilities to deploy an upgraded Cyclops Blink botnet. The new variant runs on 64‑bit Linux, adds network scanning, and is linked to recent ransomware activity. Cisco urges immediate patching, but broader hardening is still pending.
- Sandworm exploited two Cisco FMC CVEs (CVE‑2026‑20079 & CVE‑2026‑20316) to deliver Cyclops Blink.
- The latest variant operates on 64‑bit Linux and adds active network scanning and packet capture.
- High confidence links the campaign to Sandworm, a state‑sponsored Russian actor.
In a sophisticated attack, a Russian threat actor has chained two vulnerabilities in Cisco’s Firewall Management Center (FMC) to deploy an upgraded Cyclops Blink botnet. The malware, originally discovered in 2022, has now been adapted to 64‑bit x86‑64 Linux and can harvest credentials, scan internal networks, and capture live traffic.
Cisco identified the exploit chain as involving CVE‑2026‑20079, an authentication bypass that allows unauthenticated remote code execution, and CVE‑2026‑20316, a lower‑severity flaw that permits low‑privilege login and subsequent privilege escalation. The attacker first installs a Netcat‑based reverse shell, then uses it to download and run Cyclops Blink.
According to Sophos, the new variant expands its data‑collection scope to include password hashes, process command lines, CPU information, and configuration data. This enhances its reconnaissance capabilities across a broader range of Linux‑based network appliances.
Why This Matters
BozokMedia analysis shows that compromising network‑management infrastructure provides attackers a privileged viewpoint into the entire environment, enabling traffic observation, network probing, and secondary attacks.
"This attack demonstrates how attackers can leverage network device vulnerabilities to harvest vast amounts of data and launch further exploits.”
Frequently Asked Questions
1. What is Cyclops Blink? Cyclops Blink is a modular botnet and backdoor that reports infected devices to command‑and‑control servers and can download additional malicious modules.
2. What steps should organizations take? Apply Cisco’s hotfixes immediately, enable enhanced monitoring on FMC devices, and await the forthcoming hardened release that addresses all related vulnerabilities.