Cyclops Blink Returns with Expanded Capabilities

Summary
Sophos researchers analyzed a Cyclops Blink variant found on compromised Cisco FMC devices. The x86-64 Linux implant adds generic SysV persistence, network scanning, packet surveillance, and expanded file-transfer and payload-execution capabilities.
Key points
- Researchers found the 64-bit Linux executable timezone_check on multiple compromised Cisco Firewall Management Center devices; it provides persistent remote access.
- The five-module implant collects host details, transfers files and executes payloads, scans internal networks, and selectively captures packets matching operator-defined terms.
- It persists as /lib/tz/timezone_check through a SysV init service, broadening potential compatibility beyond the WatchGuard-specific 2022 version.
- The implant uses TLS and a custom C2 protocol; analyzed samples beaconed hourly to 89[.]34[.]96[.]56 over TCP port 43856 or 49172.
- CTU assesses a Russian nexus with high confidence and an association with IRON VIKING with moderate confidence; the group attribution is not conclusive.
- Sophos recommends hunting beyond Cisco FMC across compatible Linux-based network appliances. Indicators include the implant path, C2 address, and a distinctive User-Agent string.
Article Details
- Attack Vectors
- The 2026 Cyclops Blink variant was discovered on compromised Cisco Firewall Management Center (FMC) devices; the initial access method was not disclosed.
- The implant persists by copying itself to /lib/tz/timezone_check and registering a SysV init service with startup links for runlevels 2 through 5.
- Worker modules collect host information, scan connected IPv4 networks and services, selectively capture network packets, transfer files, and execute downloaded payloads.
- The controller communicates with C2 infrastructure over TLS and can receive changes to its C2 addresses and beacon timing.
- Defensive Notes
- Hunt compatible Linux-based network appliances beyond Cisco FMC for the documented persistence files, disguised process, outbound C2 activity, scanning, and packet-capture behavior.
- The Sophos countermeasure identified for this threat is Linux/Agnt-JG.
- Successful installation under /lib and /etc requires sufficient write permissions; the analyzed persistence code does not provide privilege escalation.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 89[.]34[.]96[.]56 | Hard-coded Cyclops Blink C2 server address in the analyzed samples. |
MITRE ATT&CK
T1003.008 · /etc/passwd and /etc/shadowWith sufficient privileges, module 0x08 may access /etc/shadow and expose password hashes for offline analysis.T1016 · System Network Configuration DiscoveryModule 0x08 collects network interfaces, addresses, ARP data, and resolver configuration.T1036.005 · Match Legitimate Resource Name or LocationThe controller presents itself as [kworker/0:1], while its installation path and service name resemble Linux time zone components.T1037.004 · RC ScriptsThe implant creates a SysV init script and runlevel 2 through 5 startup links to launch automatically.T1040 · Network SniffingModule 0x12 captures raw network traffic and retains packets matching operator-supplied content patterns.T1041 · Exfiltration Over C2 ChannelThe implant can upload local files and sends collected host details, scan findings, and captured packets through its C2 channel.T1046 · Network Service DiscoveryModule 0x11 probes connected IPv4 networks for open ports and service responses.T1057 · Process DiscoveryModule 0x08 collects process and command-line information.T1082 · System Information DiscoveryModule 0x08 collects operating system, kernel, processor, memory, filesystem, and storage details from the compromised host.T1105 · Ingress Tool TransferModule 0x0F downloads content over HTTP or HTTPS and can execute retrieved payloads or load additional implant modules.T1562.004 · Disable or Modify System FirewallThe controller adds iptables OUTPUT ACCEPT rules for its outbound C2 ports.T1571 · Non-Standard PortThe controller attempts TLS-protected C2 connections on TCP ports 43856 and 49172.
Threat Actors
IRON VIKINGCTU assesses a moderate-confidence association with the 2026 activity and says it tracks Sandworm as IRON VIKING; the article also identifies Seashell Blizzard as another name for the group.SandwormIdentified as another name for IRON VIKING; UK and U.S. government agencies previously attributed Cyclops Blink to Sandworm. CTU's association of the group with the 2026 activity is moderate confidence.Seashell BlizzardIdentified as another name for IRON VIKING, whose association with the 2026 activity CTU assesses with moderate confidence.
Malware
Vendors
Ciscoa malicious 64-bit Linux executable named timezone_check that was discovered on multiple compromised Cisco Firewall Management Center (FMC) devices. The sophisticated modular implant provides persistent remoteSophosThe following Sophos countermeasure relates to this threat:WatchGuardUnlike the WatchGuard-focused samples documented in 2022, the 2026 variant runs on x86-64 Linux and uses generic System V (SysV) persistence rather than vendor-specific firmware modification. This change broadens the