{"id":18711,"date":"2026-09-14T13:07:45","date_gmt":"2026-09-14T13:07:45","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=18711"},"modified":"2026-09-14T13:07:45","modified_gmt":"2026-09-14T13:07:45","slug":"sandworm-linked-cyclops-blink-returns-with-community-scanning-and-packet-sniffing-capabilities","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=18711","title":{"rendered":"Sandworm-Linked Cyclops Blink Returns With Community Scanning and Packet-Sniffing Capabilities"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">A newly recognized Cyclops Blink variant has resurfaced on compromised Cisco Safe Firewall Administration Heart (FMC) home equipment, including lively internal-network scanning and programmable packet-sniffing capabilities to an already mature modular implant. <\/p>\n<p class=\"wp-block-paragraph\">Assessed with excessive confidence that the exercise has a Russian nexus, with a moderate-confidence hyperlink to IRON VIKING additionally tracked as Sandworm and Seashell Blizzard.<\/p>\n<p class=\"wp-block-paragraph\">Cisco Talos publicly disclosed the broader FMC exploitation exercise on September 9, warning that attackers abused two vulnerabilities CVE-2026-20079 and CVE-2026-20316 to achieve entry, deploy reverse shells and proxy tooling, steal gadget information, and in the end set up Cyclops Blink. <\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-20079 is an authentication-bypass flaw that may permit unauthenticated distant attackers to execute scripts and procure root entry on affected FMC units, whereas CVE-2026-20316 allows login with a low-privileged account.<\/p>\n<p class=\"wp-block-paragraph\">The event marks a big evolution for Cyclops Blink, a malware household publicly attributed by U.S. and UK authorities to the GRU-linked Sandworm operation in 2022. <\/p>\n<p class=\"wp-block-paragraph\">Earlier samples primarily focused <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/watchguard-firebox-flaw\/\" data-type=\"post\" data-id=\"168674\" target=\"_blank\" rel=\"noreferrer noopener\">WatchGuard Firebox units<\/a> working 32-bit PowerPC Linux. <\/p>\n<p class=\"wp-block-paragraph\">The newly noticed construct is a 64-bit x86-64 ELF implant with generic System V init persistence, doubtlessly making it moveable throughout a wider set of Linux-based network-management, VPN, routing and safety home equipment.<\/p>\n<p class=\"wp-block-paragraph\">The timezone_check implant operates via a dad or mum controller and 5 forked employee modules. <\/p>\n<p class=\"wp-block-paragraph\">The controller disguises itself as [kworker\/0:1], a reputation meant to resemble respectable Linux kernel-worker exercise in course of listings. <\/p>\n<p class=\"wp-block-paragraph\">It coordinates its modules over devoted inter-process communication channels, synchronizes configuration, encrypts collected output and relays it over TLS-protected outbound command-and-control connections.<\/p>\n<p class=\"wp-block-paragraph\">The controller additionally modifies native firewall coverage to protect its C2 entry. It provides iptables OUTPUT-chain ACCEPT guidelines for TCP ports 43856 and 49172, the ports utilized by the implant\u2019s C2 communications. <\/p>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.sophos.com\/en-gb\/blog\/-eye-spy-cyclops-blink-returns-with-extended-capabilities\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Researchers at Sophos Counter Menace Unit (CTU) analyzed<\/a>, the 64-bit Linux executable, named timezone_check, in August 2026.<\/p>\n<h2 id=\"h-cyclops-blink-variant\" class=\"wp-block-heading\"><strong>Cyclops Blink variant <\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The malware incorporates a hard-coded C2 handle, 89[.]34[.]96[.]56, and makes an attempt TLS periods with out standard certificates validation, then exchanges information via a customized protocol slightly than HTTP.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/images.contentstack.io\/v3\/assets\/blt38f1f401b66100ad\/blt02bc2acd6997bfd8\/6aa429cd86010ed780098ea8\/CyclopsBlink2609fig1.png\" alt=\"Cyclops Blink architecture (Source : Sophos).\"\/><figcaption class=\"wp-element-caption\"><em>Cyclops Blink structure<\/em> (Supply : Sophos).<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Its C2 configuration could be remotely adjusted: operators can change C2 addresses, pressure an instantaneous beacon, change connection timing, restart the implant or load alternative employee modules. <\/p>\n<p class=\"wp-block-paragraph\">This modular design gives resilience and permits a number of surveillance or post-compromise duties to run concurrently.<\/p>\n<p class=\"wp-block-paragraph\">Probably the most consequential additions are modules for community discovery and selective visitors assortment. <\/p>\n<p class=\"wp-block-paragraph\">Module 0x11 enumerates regionally linked IPv4 networks and scans both attacker-specified ranges or an embedded listing of ports linked to administration, file-sharing, net, listing, VPN, VMware and network-management providers.<\/p>\n<p class=\"wp-block-paragraph\">The scanner sends crafted Ethernet, IPv4 and TCP frames over uncooked packet sockets, identifies open ports via SYN-ACK replies, performs light-weight TCP handshakes and might retrieve HTTP responses or conduct TLS probing. <\/p>\n<p class=\"wp-block-paragraph\">Its built-in targets embrace SSH, Telnet, SMB, LDAP, DNS, SNMP, VMware providers, HTTP\/HTTPS and VPN-related ports. <\/p>\n<p class=\"wp-block-paragraph\">From an FMC\u2019s privileged place, this functionality might expose inside administration programs and providers not reachable from the general public web.<\/p>\n<p class=\"wp-block-paragraph\">Module 0x12 provides focused packet seize. It opens an AF_PACKET uncooked socket to gather seen Ethernet frames, parses IPv4 TCP and UDP payloads, and searches them utilizing an Aho-Corasick-style multi-pattern matching routine. <\/p>\n<p class=\"wp-block-paragraph\">As an alternative of exfiltrating all visitors, operators can configure length, protocol and handle filters, ports, and content material phrases. <\/p>\n<p class=\"wp-block-paragraph\">Matching packets are retained in timestamped pcap-style data, doubtlessly exposing cleartext credentials, authentication cookies, entry tokens, administrative instructions and delicate software information.<\/p>\n<p class=\"wp-block-paragraph\">The malware maintains persistence by copying itself to \/lib\/tz\/timezone_check, creating \/and so on\/init.d\/timezone_check, and putting in SysV startup hyperlinks for runlevels 2 via 5. <\/p>\n<p class=\"wp-block-paragraph\">The time zone-themed paths and repair title are meant to seem benign. Profitable set up additionally strongly suggests execution with root-level permissions as a result of the implant should write beneath \/lib and \/and so on.<\/p>\n<p class=\"wp-block-paragraph\">A separate module helps file uploads, HTTP\/HTTPS downloads, arbitrary payload execution and in-memory code loading. <\/p>\n<p class=\"wp-block-paragraph\">It may possibly register downloaded ELF binaries as further modules, permitting operators to broaden the implant with out changing your complete framework. <\/p>\n<p class=\"wp-block-paragraph\">The module additionally makes use of Google Public DNS at 8.8.8.8 over <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/chrome-78\/\" data-type=\"post\" data-id=\"38374\" target=\"_blank\" rel=\"noreferrer noopener\">DNS-over-HTTPS entry<\/a> to resolve transfer-host names, bypassing native resolver infrastructure and lowering standard DNS-log proof.<\/p>\n<p class=\"wp-block-paragraph\">The marketing campaign demonstrates why FMC and comparable network-edge administration programs should be handled as high-value intrusion factors. <\/p>\n<p class=\"wp-block-paragraph\">Cisco noticed UAT-11823 chaining the 2 FMC flaws earlier than putting in a Netcat reverse shell, proxy instruments and the Cyclops Blink variant. <\/p>\n<p class=\"wp-block-paragraph\">Organizations ought to instantly apply Cisco\u2019s out there hotfixes, examine FMC units for anomalous SysV providers and the timezone_check paths, evaluate outbound TLS periods on ports 43856 and 49172, and hunt for raw-socket scanning, uncommon inside probes and suspicious packet-capture habits.<\/p>\n<p class=\"wp-block-paragraph\">The renewed framework is just not merely a persistence implant. <\/p>\n<p class=\"wp-block-paragraph\">On a compromised management-plane equipment, Cyclops Blink can develop into an inside reconnaissance platform, a selective network-surveillance sensor and a staging level for broader Sandworm-linked operations.<\/p>\n<h2 id=\"h-iocs\" class=\"wp-block-heading\"><strong>IOCs<\/strong><\/h2>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Indicator<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Sort<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Context<\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">89[.]34[.]96[.]56<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">IP handle<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Cyclops Blink C2 server<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">\/lib\/tz\/timezone_check<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">File path<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Utilized by 2026 model of Cyclops Blink<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><strong>Be aware:<\/strong>\u00a0IP addresses and domains are deliberately defanged (e.g.,\u00a0<code>[.]<\/code>) to stop unintended decision or hyperlinking. Re-fang solely inside managed menace intelligence platforms similar to MISP, VirusTotal, or your SIEM.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong>\u2605 <strong>Study 7 Metric-Gated AI SOC Deployment Phases \u2013 <strong><strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/underdefense.com\/ai-soc-deployment-playbook-from-assessment-to-autonomy\/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Obtain Free AI SOC Deployment Playbook 2026<\/a><\/strong><\/strong>.<\/strong><\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A newly recognized Cyclops Blink variant has resurfaced on compromised Cisco Safe Firewall Administration Heart (FMC) home equipment, including lively internal-network scanning and programmable packet-sniffing capabilities to an already mature modular implant. Assessed with excessive confidence that the exercise has a Russian nexus, with a moderate-confidence hyperlink to IRON VIKING additionally tracked as Sandworm and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":18713,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[10548,610,10547,299,10549,920,10546,5077],"class_list":["post-18711","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-blink","tag-capabilities","tag-cyclops","tag-network","tag-packetsniffing","tag-returns","tag-sandwormlinked","tag-scanning"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18711","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=18711"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18711\/revisions"}],"predecessor-version":[{"id":18712,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18711\/revisions\/18712"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/18713"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=18711"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=18711"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=18711"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}