
A likely Russian threat actor is deploying a sophisticated malware implant capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices by chaining two vulnerabilities in Cisco's Firewall Management Center (FMC) technology.
In separate reports, Sophos and Cisco identified the malware as a new version of Cyclops Blink, a modular botnet and backdoor that US and UK government agencies have previously linked to Sandworm, a threat actor with ties to Russia's Main Intelligence Directorate (GRU).
Two Separate Cisco FMC Vulnerabilities
Cisco described the Cyclops Blinks activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software. One of the vulnerabilities is CVE-2026-20079, a maximum severity authentication bypass vulnerability that lets an unauthenticated remote attacker run arbitrary code on affected devices and gain root access to the underlying operating system. The second vulnerability, tracked as CVE-2026-20316, is a lower-severity flaw with a 5.3 CVSS score that allows a remote attacker to log in with low privileges and then use other previous FMC vulnerabilities to escalate privileges.
Threat actors possibly tied to Sandworm are chaining the two flaws to first download a Netcat-based reverse shell and proxy tool on vulnerable FMC systems and then use that to deploy the new Cyclops Blink variant.
Cisco released hotfixes for both bugs last week and "strongly advised" organizations using the affected technology to apply them immediately, citing evidence of exploit activity in the wild. The company said it would release a broader, hardened release with fixes for the two new flaws and other internally discovered vulnerabilities in FMC later this week. "Given the in the wild abuse we strongly recommend that customers apply the referenced hotfixes as soon as possible, pending the hardening release," Cisco said.
Cyclops Blink is malware that first surfaced in 2022 and initially targeted WatchGuard firewalls and, later, ASUS devices. Its core functions included beaconing information about infected devices to command-and-control (C2) servers, downloading and executing malicious files, and adding new modules to expand its capabilities.
The malware could persist through reboots and legitimate firmware updates, making it difficult to remove. However, the FBI led a court-authorized operation in which it accessed victims' devices, copied the Cyclops Blink malware, and then removed it.
A Significant Upgrade for Cyclops Blink
The latest variant, according to Sophos, retains many of the original features while adding several new ones. The most significant change is that the malware now runs on 64-bit x86-64 Linux systems rather than the older 32-bit PowerPC architecture used by the original version. It also uses generic Linux persistence techniques instead of modifying vendor-specific firmware.
The new Cyclops Blink variant adds active network scanning and packet-capture capabilities and expands its data-collection functions to include password hashes, process command lines, CPU information, and configuration data. These changes potentially make Cyclops Blink compatible with a broader range of Linux-based network appliances and give attackers a more powerful platform for reconnaissance and intelligence collection, Sophos said.
"Generic SysV persistence in the 2026 Cyclops Blink samples removes the dependency on WatchGuard-specific firmware, while active network scanning and selective packet capture substantially expand the implant’s intelligence-collection capabilities," Sophos researchers wrote. "The discovery on Cisco FMC devices highlights the risk posed by compromised network-management infrastructure."
Compromised network appliances and other edge devices can give attackers a privileged vantage point into the broader environment and allow them to observe traffic, conduct network probes, and launch additional attacks, the vendor noted.
In addition to the new Cyclops Blink campaign, two other groups are actively exploiting CVE-2026-20079 and CVE-2026-20316. The first cluster, which Cisco Talos is tracking as UAT 12197, is exploiting CVE-2026-20079 to plant Web shells and a Java-based command execution tool to steal credentials. The other threat cluster, UAT 11988, is exploiting CVE-2026-20316 to distribute Qilin ransomware.
Sophos attributed the new Cyclops Blink campaign with high confidence to Russia-nexus actors and has moderate confidence it is associated with Sandworm, which the vendor tracks as Iron Viking. "The lower confidence in the threat group attribution reflects the absence of conclusive evidence directly linking IRON VIKING to the observed 2026 deployments," the researchers wrote.
Sandworm is a Russian state-sponsored hacking group known for both espionage and destructive cyber operations. The group has been linked to some of the most consequential cyberattacks of the past decade, including attacks that disrupted Ukraine’s power grid and the NotPetya outbreak. More recently, Sandworm has expanded its use of vulnerabilities in Internet-facing infrastructure to gain access to organizations in Ukraine and elsewhere, while continuing to target critical infrastructure and other strategically important organizations.