'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
C darkreading ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
The GRU actor Sandworm is chaining Cisco vulnerabilities to spread an upgraded Cyclops Blink variant and maintain persistent control over compromised network devices.
Description
The Russian GRU-linked group Sandworm is chaining vulnerabilities in Cisco devices to spread an updated version of the Cyclops Blink botnet malware. Cyclops Blink targets network perimeter devices such as routers and firewalls and consists of modular malware whose infrastructure was partially disrupted by an FBI operation in 2022. The current campaign uses known Cisco vulnerabilities as an entry point to take over devices and compromise them persistently. Organizations with exposed Cisco edge devices are affected, particularly in critical infrastructure and government. No specific CVE IDs or exploit details are given in the report.
Risk score
- strategic relevance
- 0.85
Path: strategic