Malware

Cyclops Blink malware linked to Russian state hackers

0

Intelligence agencies in the U.K. and the U.S. disclosed details of a new botnet malware named Cyclops Blink which is attributed to the Russian-backed Sandworm hacking group.

The malware, used by Sandworm operators had targeted WatchGuard Firebox and other Small Office/Home Office (SOHO) network devices and were deployed in attacks dating back to 2019.

Cyclops Blink appears to be a replacement for the VPNFilter malware exposed in 2018, and its deployment could allow Sandworm to remotely access networks.

WatchGuard issued its own advisory today, saying that Cyclops Blink may have affected roughly 1% of all active WatchGuard firewall appliances, which are usually used by business customers.

According to NCSC, FBI, CISA, and NSA analysis, the malware also comes with modules specifically developed to upload/download files to and from its command-and-control server, collect and exfiltrate device information, and update the malware.

The malware uses the infected devices’ legitimate firmware update channels to maintain access to compromised systems by injecting malicious code and deploying repacked firmware images.

The intelligence agencies stated that Cyclops Blink persists on reboot and throughout the legitimate firmware update process. So all the affected organizations must take steps to remove the malware.

WatchGuard has worked closely with the FBI, CISA and the NCSC, and has provided tooling and guidance to enable detection and removal of Cyclops Blink on WatchGuard devices through a non-standard upgrade process.

All accounts on infected devices should be assumed as being compromised and organizations should immediately remove Internet access to the management interface of affected network devices.

Sandworm, also tracked as Voodoo Bear, BlackEnergy, and TeleBots is an elite Russian-sponsored cyberespionage group active since the mid-2000s.

Its members are believed to be military hackers and has been linked to the BlackEnergy malware behind the Ukrainian blackouts of 2015 and 2016 as well as the KillDisk wiper attacks that targeted Ukrainian banks. Sandworm is also behind the NotPetya ransomware.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Expeditors operations impacted by cyber attack

Previous article

New data-wiping malware used in attacks on Ukraine

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *