A variant of the Cyclops Blink malware targeting Cisco Firewall Management Center devices. The modular implant provides persistent remote access to compromised Linux systems and is associated with the Russia-based IRON VIKING threat group. Unlike previous variants, this version runs on x86-64 Linux and uses generic System V persistence. The implant’s expanded capabilities include active network and service discovery, programmable packet surveillance, file transfer, and payload execution, allowing a compromised device to serve as a platform for internal reconnaissance, intelligence collection, and follow-on operations.
The Cyclops Blink architecture consists of a parent controller and five child-process worker modules that perform host reconnaissance, file transfer and payload execution, active network discovery, selective packet capture, and persistence.[/subscribe_to_unlock_form]
A variant of the Cyclops Blink malware targeting Cisco Firewall Management Center devices. The modular implant provides persistent remote access to compromised Linux systems and is associated with the Russia-based IRON VIKING threat group. Unlike previous variants, this version runs on x86-64 Linux and uses generic System V persistence. The implant’s expanded capabilities include active network and service discovery, programmable packet surveillance, file transfer, and payload execution, allowing a compromised device to serve as a platform for internal reconnaissance, intelligence collection, and follow-on operations.
The Cyclops Blink architecture consists of a parent controller and five child-process worker modules that perform host reconnaissance, file transfer and payload execution, active network discovery, selective packet capture, and persistence.[emaillocker id="1283"]
The controller maintains a fixed-size status structure distributed to every registered worker module, keeping independently executing worker processes synchronized with changes to shared configuration and controller state. The threat has significant implications for defenders, who must be aware of the expanded capabilities and potential use cases for this malware.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Discovery | T1082 | System Information Discovery | - |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
The following reports contain further technical details:
[/emaillocker]