Threat Advisory

Cyclops Blink Malware Grants Remote Access to Compromised Linux Systems

Threat: Malware
Targeted Region: United Kingdom, Russia
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A variant of the Cyclops Blink malware targeting Cisco Firewall Management Center devices. The modular implant provides persistent remote access to compromised Linux systems and is associated with the Russia-based IRON VIKING threat group. Unlike previous variants, this version runs on x86-64 Linux and uses generic System V persistence. The implant’s expanded capabilities include active network and service discovery, programmable packet surveillance, file transfer, and payload execution, allowing a compromised device to serve as a platform for internal reconnaissance, intelligence collection, and follow-on operations.

The Cyclops Blink architecture consists of a parent controller and five child-process worker modules that perform host reconnaissance, file transfer and payload execution, active network discovery, selective packet capture, and persistence.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A variant of the Cyclops Blink malware targeting Cisco Firewall Management Center devices. The modular implant provides persistent remote access to compromised Linux systems and is associated with the Russia-based IRON VIKING threat group. Unlike previous variants, this version runs on x86-64 Linux and uses generic System V persistence. The implant’s expanded capabilities include active network and service discovery, programmable packet surveillance, file transfer, and payload execution, allowing a compromised device to serve as a platform for internal reconnaissance, intelligence collection, and follow-on operations.

The Cyclops Blink architecture consists of a parent controller and five child-process worker modules that perform host reconnaissance, file transfer and payload execution, active network discovery, selective packet capture, and persistence.[emaillocker id="1283"]

The controller maintains a fixed-size status structure distributed to every registered worker module, keeping independently executing worker processes synchronized with changes to shared configuration and controller state. The threat has significant implications for defenders, who must be aware of the expanded capabilities and potential use cases for this malware.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Persistence T1543.003 Create or Modify System Process Windows Service
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Discovery T1082 System Information Discovery -
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu