Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Cyclops Blink Malware Targets Corporate Networks

New Cyclops Blink Malware Targets Corporate Networks

Posted on September 15, 2026 By CWS

Cyclops Blink Returns with Enhanced Capabilities

The notorious Cyclops Blink malware is back with advanced features that allow cyber attackers to gain a comprehensive view of corporate networks. Recently detected on compromised Cisco Firewall Management Center devices, this malware facilitates remote access, traffic inspection, and mapping of internal systems.

The presence of Cyclops Blink on management appliances is particularly alarming due to their trusted network positions. Breaches at this level can expose critical configurations, credentials, and pathways to otherwise secure systems, highlighting the significant risk posed by such intrusions.

Identifying the Threat

In August, Sophos researchers uncovered the latest Cyclops Blink implant while analyzing a malicious 64-bit Linux executable on compromised devices. The analysis linked this malware to the Sandworm group associated with Russia, though attribution for recent deployments remains cautious.

The initial access point for the malware remains undetermined. However, the affected environments have faced significant web-management vulnerabilities, including the exploitation of embedded credentials that allowed unauthorized access, potentially compounding security risks.

Evolution of Cyclops Blink Malware

The updated Cyclops Blink sample is now a 64-bit x86-64 Linux executable, moving away from its previous PowerPC version found on WatchGuard devices. This new version leverages standard SysV startup services, enhancing its persistence across various Linux systems.

With elevated privileges, the implant relocates to a system directory, registering a startup script for automatic execution post-reboot. It disguises its controller as a regular Linux worker process, minimizing detection risk in process listings.

The malware operates through five child-process modules, each handling tasks like reconnaissance, file transfer, scanning, packet collection, and maintaining persistence, all managed by a parent controller.

Implications for Network Security

Cyclops Blink profiles host systems and their nearby networks, gathering data on operating systems, accounts, processes, storage, and more. When permissions allow, it can extract password hashes and exfiltrate accessible files, enhancing its threat to network management platforms.

Its command-and-control mechanism uses outbound TLS connections with a custom protocol, complicating network defense and incident response. Timing changes and destination tracking are crucial for effective mitigation.

The malware’s internal scanner identifies local IPv4 networks, testing ports related to administration, file sharing, and more. This functionality transforms infected devices into reconnaissance tools, aiding attackers in selecting subsequent targets.

Organizations must extend threat hunting beyond known affected devices, scrutinizing compatible Linux appliances for signs of compromise. Prompt security updates, restricted management access, and vigilant monitoring of encrypted connections are essential defensive measures.

For further protection, ensure your SOC is updated within 24 hours of malware emergence, utilizing platforms like ANYRUN for early detection.

Cyber Security News Tags:Cisco, Cybersecurity, Cyclops Blink, Linux implant, Malware, network scanning, network security, packet sniffing, Sandworm, Sophos

Post navigation

Previous Post: WhatsApp Tests New Feature to Lock Chats on Primary Phone
Next Post: Critical Linux Kernel Flaw Allows Privilege Escalation

Related Posts

GitLab Resolves 13 Security Issues Affecting Data and Pipelines GitLab Resolves 13 Security Issues Affecting Data and Pipelines Cyber Security News
China-based Threat Actor Mustang Panda’s Tactics, Techniques, and Procedures Unveiled China-based Threat Actor Mustang Panda’s Tactics, Techniques, and Procedures Unveiled Cyber Security News
Introducing Pentest Swarm AI: Revolutionizing Autonomous Penetration Testing Introducing Pentest Swarm AI: Revolutionizing Autonomous Penetration Testing Cyber Security News
Hackers Attempted to Misuse Claude AI to Launch Cyber Attacks Hackers Attempted to Misuse Claude AI to Launch Cyber Attacks Cyber Security News
STX RAT Emerges as a Stealthy Cyber Threat STX RAT Emerges as a Stealthy Cyber Threat Cyber Security News
OilRig Hides C2 Data in Images on Google Drive with Steganography OilRig Hides C2 Data in Images on Google Drive with Steganography Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Linux Kernel Flaw Allows Privilege Escalation
  • New Cyclops Blink Malware Targets Corporate Networks
  • WhatsApp Tests New Feature to Lock Chats on Primary Phone
  • Microsoft’s $30,000 Bounty for AI Vulnerabilities
  • Critical Nintendo Switch Flaw Allows Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Linux Kernel Flaw Allows Privilege Escalation
  • New Cyclops Blink Malware Targets Corporate Networks
  • WhatsApp Tests New Feature to Lock Chats on Primary Phone
  • Microsoft’s $30,000 Bounty for AI Vulnerabilities
  • Critical Nintendo Switch Flaw Allows Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark