The US government announced that they had disrupted the Cyclops Blink botnet controlled by the Russian-backed Sandworm hacking group.
The malware which was used by Sandworm to create this botnet since at least June 2019, is targeting WatchGuard Firebox firewall appliances and multiple ASUS router models.
Cyclops Blink enables the attackers to establish persistence on the device through firmware updates, providing remote access to compromised networks. This malware is modular, so it is easy to upgrade to target new devices and tap into new pools of exploitable hardware.
US Attorney General Merrick Garland announced about the disruption and stated that the Russian government has recently used similar infrastructure to attack Ukrainian targets. He thanked the international partners for working with them to detect the infection of thousands of network hardware devices.
Following this US Justice Department operation’s initial March 18 court authorization, the malware was removed from all remaining identified Watchguard devices acting as command and control servers.
The FBI also notified owners of compromised devices in the United States and abroad through foreign law enforcement partners before removing the Cyclops Blink malware. The US victims whose contact info was not found were contacted by their providers following notices issued by the FBI.
FBI Director Chris Wray said the botnet was disrupted following close cooperation with Watchguard while analyzing the malware and developing detection tools and remediation techniques.
He warned that any Firebox devices that acted as bots, may still remain vulnerable in the future until mitigated by their owners. So the owners are recommended to adopt Watchguard’s detection and remediation steps as soon as possible.
WatchGuard has shared detailed instructions on how to restore compromised Firebox appliances to a clean state to remediate the infection and update them to the latest Fireware OS version to prevent future infections.
Sandworm, also tracked as Voodoo Bear, BlackEnergy, and TeleBots, the group behind the Cyclops Blink botnet, is a Russian-sponsored hacking group active since the mid-2000s. Its operators are believed to be Russian military hackers part of Unit 74455 of the Russian GRU’s Main Center for Special Technologies.
















Comments