LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0687: Cyclops Blink

Cyclops Blink is a modular malware that has been used in widespread campaigns by Sandworm Team since at least 2019 to target Small/Home Office (SOHO) network devices, including WatchGuard and Asus. Cyclops Blink is assessed to be a replacement for VPNFilter, a similar platform targeting network devices.[1][2][3]

EnterpriseS0687MalwareObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Cyclops Blink matters because it targets network devices rather than ordinary endpoints. Compromise of routers, firewalls, or SOHO edge devices can undermine perimeter trust, remote access paths, and incident response visibility. The supplied ATT&CK record describes a modular malware platform used by Sandworm Team since at least 2019 against SOHO network devices, including WatchGuard and Asus, and assessed as a replacement for VPNFilter.

Executive priority

Treat this as a resilience and visibility issue for unmanaged or lightly managed network infrastructure. Leaders should ask whether the organization has an accurate inventory of edge/SOHO network devices, whether firmware and configuration integrity can be proven, whether device logs are centrally collected, and whether incident response plans include network-device containment and rebuild decisions. This is also relevant to audit evidence because many controls depend on firewalls and routers remaining trustworthy.

Technical view

ATT&CK provides no dedicated detection text for Cyclops Blink, so validation should be relationship-driven. The related techniques point to discovery on network devices, persistence through RC scripts and possible firmware-related persistence, C2 over web protocols, non-standard ports, protocol tunneling, asymmetric cryptography, multi-hop proxying, ingress tool transfer, exfiltration over C2, timestomping, and network-device firewall rule changes. SOC and IR teams should confirm whether network-device telemetry is sufficient to observe configuration changes, startup script modifications, process/file enumeration, suspicious outbound web traffic, atypical port/protocol pairings, and unauthorized firewall/ACL changes.

Likely telemetry

  • Network device inventory and firmware/version records
  • Network device system, authentication, configuration, and administrative change logs
  • Firewall, ACL, security zone, and policy change history
  • Outbound network flow records from edge and SOHO devices
  • Proxy, DNS, and web traffic metadata for device-originated connections

Detection direction

  • Do not rely only on endpoint EDR; the ATT&CK platform is Network Devices, where telemetry is often sparse or absent.
  • Baseline expected management activity, firmware versions, startup scripts, firewall rules, and outbound destinations for network devices, then alert on unauthorized drift.
  • Tune for device-originated web traffic on unusual ports, protocol/port mismatches, encrypted or encoded sessions that do not match normal device behavior, and repeated connections through proxy-like infrastructure.
  • Correlate discovery behaviors such as process, file, directory, system, and network configuration enumeration with subsequent tool transfer, C2, or exfiltration-like traffic.
  • Review firewall and ACL modifications as security events, not just network operations, because the related technique includes network-device firewall impairment.

Mitigation priorities

  • Prioritize authoritative inventory of network devices, including SOHO and edge equipment that may sit outside normal endpoint management.
  • Maintain firmware and configuration management processes that can prove current state and detect unauthorized changes.
  • Restrict and monitor administrative access to network devices; separate routine operations from emergency access paths.
  • Centralize network-device logs and retain configuration-change history for investigation and compliance evidence.
  • Limit unnecessary outbound traffic from network devices and review allowed destinations, ports, and protocols.
Additional notes and limits

The business risk is amplified by the device class: compromised routers or firewalls can provide persistence, traffic relay, C2, and policy manipulation while avoiding many endpoint-focused controls. The relationship to Sandworm Team is supplied by ATT&CK, but this take does not infer current activity against any specific organization. The most useful defensive work is proving whether network-device telemetry and change control are strong enough to make this behavior observable.

The official ATT&CK object does not provide detection guidance, aliases, labels, or malware-level tactics. Several technical conclusions are derived from supplied ATT&CK relationships rather than a Cyclops Blink-specific detection section. Local device models, firmware, logging capability, network architecture, and administrative practices are required to determine actual exposure and coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Cyclops Blink

Cyclops Blink is a modular malware that has been used in widespread campaigns by Sandworm Team since at least 2019 to target Small/Home Office (SOHO) network devices, including WatchGuard and Asus. Cyclops Blink is assessed to be a replacement for VPNFilter, a similar platform targeting network devices.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

21 rows
DomainIDNameRelationship / procedure
EnterpriseT1106Native API

Cyclops Blink can use various Linux API functions including those for execution and discovery.[1]

EnterpriseT1573.002Asymmetric CryptographySub-technique

Cyclops Blink can encrypt C2 messages with AES-256-CBC sent underneath TLS. OpenSSL library functions are also used to encrypt each message using a randomly generated key and IV, which are then encrypted using a hard-coded RSA public key.[1]

EnterpriseT1070.006TimestompSub-technique

Cyclops Blink has the ability to use the Linux API function `utime` to change the timestamps of modified firmware update images.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Cyclops Blink can rename its running process to [kworker:0/1] to masquerade as a Linux kernel thread. Cyclops Blink has also named RC scripts used for persistence after WatchGuard artifacts.[1]

EnterpriseT1082System Information Discovery

Cyclops Blink has the ability to query device information.[1]

EnterpriseT1542.002Component FirmwareSub-technique

Cyclops Blink has maintained persistence by patching legitimate device firmware when it is downloaded, including that of WatchGuard devices.[1]

EnterpriseT1005Data from Local System

Cyclops Blink can upload files from a compromised host.[1]

EnterpriseT1083File and Directory Discovery

Cyclops Blink can use the Linux API `statvfs` to enumerate the current working directory.[1][3]

EnterpriseT1041Exfiltration Over C2 Channel

Cyclops Blink has the ability to upload exfiltrated files to a C2 server.[1]

EnterpriseT1057Process Discovery

Cyclops Blink can enumerate the process it is currently running under.[1]

EnterpriseT1016System Network Configuration Discovery

Cyclops Blink can use the Linux API `if_nameindex` to gather network interface names.[1][3]

EnterpriseT1132.002Non-Standard EncodingSub-technique

Cyclops Blink can use a custom binary scheme to encode messages with specific commands and parameters to be executed.[1]

EnterpriseT1090.003Multi-hop ProxySub-technique

Cyclops Blink has used Tor nodes for C2 traffic.[2]

EnterpriseT1559Inter-Process Communication

Cyclops Blink has the ability to create a pipe to enable inter-process communication.[3]

EnterpriseT1686.002Network Device FirewallSub-technique

Cyclops Blink can modify the Linux iptables firewall to enable C2 communication on network devices via a stored list of port numbers.[1][3]

EnterpriseT1105Ingress Tool Transfer

Cyclops Blink has the ability to download files to target systems.[1][3]

EnterpriseT1071.001Web ProtocolsSub-technique

Cyclops Blink can download files via HTTP and HTTPS.[1][3]

EnterpriseT1037.004RC ScriptsSub-technique

Cyclops Blink has the ability to execute on device startup, using a modified RC script named S51armled.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

Cyclops Blink can decrypt and parse instructions sent from C2.[1]

EnterpriseT1572Protocol Tunneling

Cyclops Blink can use DNS over HTTPS (DoH) to resolve C2 nodes.[3]

EnterpriseT1571Non-Standard Port

Cyclops Blink can use non-standard ports for C2 not typically associated with HTTP or HTTPS traffic.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
f4d8cfa420832fc6...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundlef4d8cfa42083…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  2. [2]
    NCSC CISA Cyclops Blink Advisory February 2022

    NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022.

    Open source URL
  3. [3]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  4. [4]
    NCSC CISA Cyclops Blink Advisory February 2022

    NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022.

    Open source URL
  5. [5]
    NCSC CISA Cyclops Blink Advisory February 2022

    NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022.

    Open source URL
  6. [6]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  7. [7]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  8. [8]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  9. [9]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  10. [10]
    mitre-attackS0687
    Open source URL
  11. [11]
    mitre-attackS0687
    Open source URL
  12. [12]
    mitre-attackS0687
    Open source URL
  13. [13]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  14. [14]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  15. [15]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  16. [16]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  17. [17]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  18. [18]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  19. [19]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  20. [20]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  21. [21]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  22. [22]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  23. [23]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  24. [24]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  25. [25]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  26. [26]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  27. [27]
    NCSC CISA Cyclops Blink Advisory February 2022

    NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022.

    Open source URL
  28. [28]
    NCSC CISA Cyclops Blink Advisory February 2022

    NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022.

    Open source URL
  29. [29]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  30. [30]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  31. [31]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  32. [32]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  33. [33]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  34. [34]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  35. [35]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  36. [36]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  37. [37]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  38. [38]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  39. [39]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  40. [40]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  41. [41]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  42. [42]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  43. [43]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  44. [44]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  45. [45]
    NCSC CISA Cyclops Blink Advisory February 2022

    NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022.

    Open source URL
  46. [46]
    NCSC CISA Cyclops Blink Advisory February 2022

    NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022.

    Open source URL
  47. [47]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  48. [48]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  49. [49]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  50. [50]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  51. [51]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  52. [52]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  53. [53]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  54. [54]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  55. [55]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  56. [56]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  57. [57]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  58. [58]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  59. [59]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  60. [60]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  61. [61]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  62. [62]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.