Cyclops Blink Returns with Expanded Capabilities

· Original article ↗

Summary

Sophos researchers analyzed a Cyclops Blink variant found on compromised Cisco FMC devices. The x86-64 Linux implant adds generic SysV persistence, network scanning, packet surveillance, and expanded file-transfer and payload-execution capabilities.

Key points

  • Researchers found the 64-bit Linux executable timezone_check on multiple compromised Cisco Firewall Management Center devices; it provides persistent remote access.
  • The five-module implant collects host details, transfers files and executes payloads, scans internal networks, and selectively captures packets matching operator-defined terms.
  • It persists as /lib/tz/timezone_check through a SysV init service, broadening potential compatibility beyond the WatchGuard-specific 2022 version.
  • The implant uses TLS and a custom C2 protocol; analyzed samples beaconed hourly to 89[.]34[.]96[.]56 over TCP port 43856 or 49172.
  • CTU assesses a Russian nexus with high confidence and an association with IRON VIKING with moderate confidence; the group attribution is not conclusive.
  • Sophos recommends hunting beyond Cisco FMC across compatible Linux-based network appliances. Indicators include the implant path, C2 address, and a distinctive User-Agent string.

Article Details

Attack Vectors
  • The 2026 Cyclops Blink variant was discovered on compromised Cisco Firewall Management Center (FMC) devices; the initial access method was not disclosed.
  • The implant persists by copying itself to /lib/tz/timezone_check and registering a SysV init service with startup links for runlevels 2 through 5.
  • Worker modules collect host information, scan connected IPv4 networks and services, selectively capture network packets, transfer files, and execute downloaded payloads.
  • The controller communicates with C2 infrastructure over TLS and can receive changes to its C2 addresses and beacon timing.
Defensive Notes
  • Hunt compatible Linux-based network appliances beyond Cisco FMC for the documented persistence files, disguised process, outbound C2 activity, scanning, and packet-capture behavior.
  • The Sophos countermeasure identified for this threat is Linux/Agnt-JG.
  • Successful installation under /lib and /etc requires sufficient write permissions; the analyzed persistence code does not provide privilege escalation.

Indicators of compromise

TypeIndicatorContext
IPV489[.]34[.]96[.]56Hard-coded Cyclops Blink C2 server address in the analyzed samples.

MITRE ATT&CK

T1003.008 · /etc/passwd and /etc/shadowWith sufficient privileges, module 0x08 may access /etc/shadow and expose password hashes for offline analysis.T1016 · System Network Configuration DiscoveryModule 0x08 collects network interfaces, addresses, ARP data, and resolver configuration.T1036.005 · Match Legitimate Resource Name or LocationThe controller presents itself as [kworker/0:1], while its installation path and service name resemble Linux time zone components.T1037.004 · RC ScriptsThe implant creates a SysV init script and runlevel 2 through 5 startup links to launch automatically.T1040 · Network SniffingModule 0x12 captures raw network traffic and retains packets matching operator-supplied content patterns.T1041 · Exfiltration Over C2 ChannelThe implant can upload local files and sends collected host details, scan findings, and captured packets through its C2 channel.T1046 · Network Service DiscoveryModule 0x11 probes connected IPv4 networks for open ports and service responses.T1057 · Process DiscoveryModule 0x08 collects process and command-line information.T1082 · System Information DiscoveryModule 0x08 collects operating system, kernel, processor, memory, filesystem, and storage details from the compromised host.T1105 · Ingress Tool TransferModule 0x0F downloads content over HTTP or HTTPS and can execute retrieved payloads or load additional implant modules.T1562.004 · Disable or Modify System FirewallThe controller adds iptables OUTPUT ACCEPT rules for its outbound C2 ports.T1571 · Non-Standard PortThe controller attempts TLS-protected C2 connections on TCP ports 43856 and 49172.

Threat Actors

Malware

Vendors

Products

Countries

Related Articles