Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Broken Clouds Humidity: 57%
Wind: 3.09 M/S

Cyclops Blink Expands Capabilities with Packet Sniffing and Internal Network Discovery on Linux Systems

Cyclops Blink Expands Capabilities with Packet Sniffing and Internal Network Discovery on Linux Systems

The Cyclops Blink malware has resurfaced with significant new capabilities, providing attackers with deeper visibility into enterprise environments. Researchers discovered the updated malware on compromised Cisco Firewall Management Center (FMC) devices, where it enables persistent remote access, internal network discovery, traffic collection, and follow-on attacks from a highly trusted network position.

The development is particularly concerning because network-management appliances often sit at the center of security infrastructure, granting visibility into configurations, credentials, and systems that are typically inaccessible from the internet. A compromise at this layer can provide attackers with broad insight into an organization's internal environment.

Security researchers at Sophos uncovered the latest variant while investigating malicious 64-bit Linux binaries deployed on multiple compromised FMC appliances.

Although the malware shares technical characteristics with the Cyclops Blink botnet previously associated with Russia-linked Sandworm operations, researchers remain cautious about attributing the 2026 activity to a specific threat actor.

New Linux Architecture Expands Deployment Options

The latest Cyclops Blink variant represents a notable evolution from the PowerPC-based version previously observed on WatchGuard devices.

The updated malware is built as a 64-bit x86-64 Linux implant, allowing it to operate across a broader range of Linux-based network appliances and infrastructure systems.

Rather than modifying device firmware, the malware leverages standard SysV initialization services to establish persistence. When elevated privileges are available, the implant copies itself into system directories and registers startup scripts that automatically relaunch the malware after reboot.

To evade casual discovery, the malware disguises its primary controller process as a legitimate Linux worker process, helping it blend into normal system activity.

Modular Design Supports Multiple Attack Functions

Researchers found that the malware separates functionality into five distinct modules managed by a central controller.

This architecture enables attackers to perform multiple operations simultaneously, including:

  • Internal reconnaissance
  • File collection and exfiltration
  • Network scanning
  • Packet capture
  • Long-term persistence

The modular approach allows operators to enable or disable capabilities as needed while maintaining a resilient foothold on compromised systems.

Credential Theft and Payload Delivery

When permissions allow, the malware can collect password hashes and other authentication data from infected devices.

Its file-transfer component supports a wide range of post-compromise activities, including:

  • Uploading stolen files to attacker-controlled infrastructure
  • Downloading additional malware over HTTP and HTTPS
  • Executing remote payloads
  • Loading Linux binaries directly into memory for fileless execution

For attackers, a compromised network-management appliance can serve as an intelligence hub, malware staging platform, and long-term persistence mechanism.

Because such appliances often maintain visibility across multiple network segments, they can also provide insight into privileged management networks and critical internal systems.

Encrypted Command-and-Control Communications

The malware communicates with operators through encrypted TLS connections using a custom command-and-control protocol rather than conventional web traffic.

Researchers observed infected systems beaconing approximately once per hour, although operators can modify both communication intervals and command servers dynamically while the malware remains active.

This flexibility can complicate detection and incident response efforts, making continuous monitoring of outbound encrypted traffic especially important.

Internal Network Scanning Capabilities

One of the most significant additions is an enhanced reconnaissance component designed to map internal environments.

The scanner automatically identifies locally connected IPv4 networks and probes either attacker-specified ports or a built-in list of commonly used enterprise services, including:

  • Administrative interfaces
  • File-sharing services
  • Directory services
  • Messaging platforms
  • Web applications
  • Network-monitoring tools
  • VPN infrastructure
  • Virtualization platforms

The module can also collect service banners and perform HTTP, HTTPS, and TLS probing to identify technologies running inside the network.

As a result, compromised management appliances become powerful reconnaissance sensors capable of identifying systems that are not directly exposed to the internet.

Packet Sniffing Enables Targeted Surveillance

A separate packet-capture module allows operators to monitor raw network traffic visible to the infected device.

Rather than indiscriminately collecting all traffic, attackers can configure filters based on:

  • IP addresses
  • Ports
  • Time periods
  • Keywords and content patterns

This selective collection allows operators to focus on high-value information such as:

  • Credentials
  • Session cookies
  • Authentication tokens
  • Administrative commands
  • Sensitive application requests

The capability significantly enhances an attacker's visibility while reducing the volume of captured data.

Defensive Recommendations

Organizations should extend threat-hunting efforts beyond known compromised devices and inspect Linux-based network appliances for indicators associated with Cyclops Blink.

Recommended actions include:

  • Apply all available Cisco security updates immediately.
  • Restrict access to management interfaces using segmentation and access controls.
  • Monitor outbound encrypted connections from management appliances.
  • Investigate unfamiliar startup services, processes, and scheduled tasks.
  • Review privileged account activity and credential exposure.
  • Examine network devices for signs of unusual scanning or packet-capture behavior.

Key Takeaway

The latest Cyclops Blink variant moves beyond traditional persistence and command execution by transforming compromised management appliances into powerful surveillance and reconnaissance platforms. Its combination of internal network scanning, targeted packet sniffing, encrypted command-and-control communications, and modular architecture gives attackers extensive visibility inside enterprise environments, making rapid detection and remediation critical for affected organizations.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.