Skip to content
Auto-CTI
Back to today
NEW Sandworm CRITICAL C3

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

C darkreading ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

The GRU actor Sandworm is chaining Cisco vulnerabilities to spread an upgraded Cyclops Blink variant and maintain persistent control over compromised network devices.

Description

The Russian GRU-linked group Sandworm is chaining vulnerabilities in Cisco devices to spread an updated version of the Cyclops Blink botnet malware. Cyclops Blink targets network perimeter devices such as routers and firewalls and consists of modular malware whose infrastructure was partially disrupted by an FBI operation in 2022. The current campaign uses known Cisco vulnerabilities as an entry point to take over devices and compromise them persistently. Organizations with exposed Cisco edge devices are affected, particularly in critical infrastructure and government. No specific CVE IDs or exploit details are given in the report.

Risk score

85
strategic relevance
0.85

Path: strategic

ESC