Skip to content

Malware

CyclopsBlink

According to CISA, Cyclops Blink appears to be a replacement framework for the VPNFilter malware exposed in 2018, and which exploited network devices, primarily small office/home office (SOHO) routers

CyclopsBlink is a Linux malware family.

Background

CISA assesses Cyclops Blink to be the successor to VPNFilter, the malware uncovered in 2018 that targeted network hardware such as small office/home office (SOHO) routers and network attached storage (NAS) devices. Operators have run Cyclops Blink since at least June 2019, roughly fourteen months after VPNFilter was taken down, and like its predecessor its targeting appears broad and untargeted rather than selective. To date the operators have focused mainly on WatchGuard and ASUS devices, though Sandworm is believed to have the ability to recompile the malware for additional architectures and firmware.


Source: Malpedia (Fraunhofer FKIE).