Skip to main content

New Sandworm malware Cyclops Blink replaces VPNFilter

The Sandworm actor has replaced the exposed VPNFilter malware with a new more advanced framework.

Art Alex via Getty Images



Note:

Note that only WatchGuard devices that were reconfigured from the manufacturer default settings to open remote management interfaces to external access could be infected

Malware overview

The malware itself is sophisticated and modular with basic core functionality to beacon (T1132.002) device information back to a server and enable files to be downloaded and executed. There is also functionality to add new modules while the malware is running, which allows Sandworm to implement additional capability as required.

The NCSC has published a malware analysis report on Cyclops Blink which provides more detail about the malware.


Post exploitation

Post exploitation, Cyclops Blink is generally deployed as part of a firmware ‘update’ (T1542.001). This achieves persistence when the device is rebooted and makes remediation harder. 

Victim devices are organised into clusters and each deployment of Cyclops Blink has a list of command and control (C2) IP addresses and ports that it uses (T1008). All the known C2 IP addresses to date have been used by compromised WatchGuard firewall devices. Communications between Cyclops Blink clients and servers are protected under Transport Layer Security (TLS) (T1071.001), using individually generated keys and certificates. Sandworm manages Cyclops Blink by connecting to the C2 layer through the Tor network:

Mitigation

Cyclops Blink persists on reboot and throughout the legitimate firmware update process. Affected organisations should therefore take steps to remove the malware. 

WatchGuard has worked closely with the FBI, CISA and the NCSC, and has provided tooling and guidance to enable detection and removal of Cyclops Blink on WatchGuard devices through a non-standard upgrade process.  Device owners should follow each step in these instructions to ensure that devices are patched to the latest version and that any infection is removed.

The WatchGuard tooling and guidance is available at: https://detection.watchguard.com/

In addition:

  • If your device is identified as infected with Cyclops Blink, you should assume that any passwords present on the device have been compromised and replace them (see NCSC password guidance for organisations).
  • You should ensure that the management interface of network devices is not exposed to the internet.

In addition:

  • If your device is identified as infected with Cyclops Blink, you should assume that any passwords present on the device have been compromised and replace them (see the NCSC's password guidance for organisations)
  • You should ensure that the management interface of network devices is not exposed to the internet


TacticTechniqueProcedure
Initial AccessT1133

External Remote Services

The actors most likely deploy modified device firmware images by exploiting an externally available service
ExecutionT1059.004

Command and Scripting Interpreter: Unix Shell

Cyclops Blink executes downloaded files using the Linux API
PersistenceT1542.001

Pre-OS Boot: System Firmware

Cyclops Blink is deployed within a modified device firmware image
 T1037.004

Boot or Logon Initialisation Scripts: RC Scripts

 Cyclops Blink is executed on device startup, using a modified RC script
Defence EvasionT1562.004

Impair Defenses: Disable or Modify System Firewall

Cyclops Blink modifies the Linux system firewall to enable C2 communication
 T1036.005

Masquerading: Match Legitimate Name or Location

Cyclops Blink masquerades as a Linux kernel thread process 
DiscoveryT1082

System Information Discovery

Cyclops Blink regularly queries device information 
Command and ControlT1090

Proxy

 T1132.002

Data Encoding: Non-Standard Encoding

Cyclops Blink command messages use a custom binary scheme to encode data
 T1008

Fallback Channels

Cyclops Blink randomly selects a C2 server from contained lists of IPv4 addresses and port numbers
 T1071.001

Application Layer Protocol: Web Protocols

Cyclops Blink can download files via HTTP or HTTPS
 T1573.002

Encrypted Channel: Asymmetric Cryptography

Cyclops Blink C2 messages are individually encrypted using AES-256-CBC and sent underneath TLS
 T1571Non-Standard Port

The list of port numbers used by Cyclops Blink includes non-standard ports not typically associated with HTTP or HTTPS traffic
ExfiltrationT1041Exfiltration Over C2 Channel

Cyclops Blink can upload files to a C2 server



Published

News type

Alert