Cyclops Blink Malware: History and Impact

Cyclops Blink Malware: History and Impact

In the complex landscape of global cybersecurity, few threats are as persistent as botnets targeting networking infrastructure. One such threat is Cyclops Blink, a sophisticated piece of malware designed to compromise routers and other networking equipment to create a covert command-and-control network.

While many cyber threats are discovered shortly after deployment, Cyclops Blink operated in the shadows for years before being brought to light by international security agencies.

Key Facts

  • First Appearance: Active since at least June 2019.
  • Public Disclosure: Reported in February 2022.
  • Reporting Agencies: NCSC (UK) and CISA (USA).
  • Primary Targets: Thousands of routers worldwide.
  • Attribution: Linked to the threat actor known as Sandworm.

The Timeline of Discovery

Evidence suggests that Cyclops Blink has been active since at least June 2019. For several years, the malware remained undetected, quietly infiltrating networking hardware to establish a foothold within various infrastructures.

The malware finally gained widespread attention in February 2022. This disclosure followed the publication of detailed security advisories from the United Kingdom's National Cybersecurity Centre (NCSC) and the United States' Cybersecurity and Infrastructure Security Agency (CISA), both of which documented the malware's presence in the wild.

[ไม่มีภาพประกอบ]

Attribution and Geopolitical Context

Analysis of the malware has linked Cyclops Blink to Sandworm, a notorious threat group. While Sandworm has a documented history of attacking Ukrainian assets, the deployment of Cyclops Blink presents a different pattern.

Notably, this specific malware did not target Ukrainian networking equipment. Because of this distinction, security experts believe that the Cyclops Blink campaign is unrelated to the Russo-Ukrainian War.

Cyclops Blink Overview
Detail Information
Earliest Known Activity June 2019
Public Warning Date February 2022
Associated Actor Sandworm
Affected Hardware Thousands of routers

Frequently Asked Questions

When was Cyclops Blink first active?

The malware has been active since at least June 2019.

Who reported the presence of Cyclops Blink?

The threat was detailed in security advisories published by the US Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cybersecurity Centre (NCSC).

Which group is responsible for this malware?

Cyclops Blink is attributed to the threat actor known as Sandworm.

Was Cyclops Blink used in the Russo-Ukrainian War?

No. Although Sandworm has attacked Ukrainian assets previously, Cyclops Blink did not target Ukrainian networking equipment and is thought to be unrelated to the conflict.

What was the scale of the infection?

The campaign was extensive, resulting in the need to clean thousands of infected routers.

References

  1. "Cyclops Blink" (PDF). National Cyber Security Centre.
  2. "Security Portal - Threat". securityportal.watchguard.com.
  3. Conger, Kate; Sanger, David E. (6 April 2022). "U.S. Says It Secretly Removed Malware Worldwide, Pre-empting Russian Cyberattacks". The New York Times. Archived from the original on 7 April 2022.
  4. Greenberg, Andy. "Russia's Sandworm Hackers Have Built a Botnet of Firewalls". Wired. Retrieved 21 March 2022.
  5. Hacquebord, Feike; Hilt, Stephen; Merces, Fernando (17 March 2022). "Cyclops Blink Sets Sights on Asus Routers". Trend Micro Inc. Retrieved 21 March 2022.