‘Sandworm’ Chains Cisco Vulnerabilities to Deploy Cyclops Blink

A Notorious Russian Threat Group is Back with an Upgraded Botnet Malware

A sophisticated malware implant capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices has been deployed by a likely Russian threat actor. This malware, identified as a new version of Cyclops Blink, chains two vulnerabilities in Cisco’s Firewall Management Center (FMC) technology to gain access to sensitive systems.

Cyclops Blink is not new; it first surfaced in 2022, targeting WatchGuard firewalls and later ASUS devices. However, this latest variant retains many of the original features while adding several new ones, making it a significant upgrade for the threat group behind it. The malware now runs on 64-bit x86-64 Linux systems, rather than the older 32-bit PowerPC architecture used by the original version.

The two vulnerabilities being exploited are in Cisco’s Secure FMC software. One is a maximum severity authentication bypass vulnerability (CVE-2026-20079), which allows an unauthenticated remote attacker to run arbitrary code on affected devices and gain root access to the underlying operating system. The other is a lower severity flaw with a 5.3 CVSS score that enables a remote attacker to log in with low privileges, then use previous FMC vulnerabilities to escalate privileges.

By chaining these two flaws, threat actors possibly tied to Sandworm can first download a Netcat-based reverse shell and proxy tool on vulnerable FMC systems and then deploy the new Cyclops Blink variant. This deployment is made possible by generic Linux persistence techniques used in the malware, which removes the dependency on vendor-specific firmware.

The expanded capabilities of this latest variant include active network scanning and packet-capture capabilities, as well as a broader range of data-collection functions that can potentially make it compatible with more Linux-based network appliances. These changes give attackers a more powerful platform for reconnaissance and intelligence collection.

Compromised network appliances and other edge devices can provide a privileged vantage point into the broader environment, allowing threat actors to observe traffic, conduct network probes, and launch additional attacks. Cisco has released hotfixes for both bugs last week and “strongly advised” organizations using affected technology to apply them immediately, citing evidence of exploit activity in the wild.

Given the severity of this vulnerability and the potential impact on compromised systems, it is crucial that organizations take immediate action to protect their networks. The practical takeaway from this threat is clear: if you are using Cisco’s FMC software, ensure that you have applied the latest hotfixes or upgrade to the hardened release as soon as possible.


Source: Dark Reading — 2026-09-14