TechNewsReel
Live

Sandworm Deploys Upgraded Cyclops Blink Botnet via Cisco FMC Flaws

Russian state-sponsored attackers are chaining two critical vulnerabilities to gain root access to network management infrastructure.

TechNewsReel Newsroom · September 15, 2026

The Russian state-sponsored threat group Sandworm is exploiting a chain of critical vulnerabilities in Cisco's Secure Firewall Management Center (FMC) to deploy an upgraded version of the Cyclops Blink botnet. This campaign targets core network-management infrastructure to establish a privileged vantage point for espionage and internal network probes.

According to reports from Cisco Talos and Dark Reading, attackers are chaining two specific flaws to achieve full system compromise. The process begins with CVE-2026-20079, a maximum-severity authentication bypass with a CVSS score of 10.0, followed by CVE-2026-20316, a privilege escalation vulnerability. Together, these allow the attackers to bypass security controls, escalate from a low-privilege login to root access, and install a modular Linux-based implant.

Evolution of Cyclops Blink

The original Cyclops Blink botnet first appeared in 2022, targeting ASUS and WatchGuard devices as a successor to the VPNFilter botnet, before being disrupted by a court-authorized FBI operation that same year. However, the 2026 variant represents a significant architectural shift. The malware has transitioned from 32-bit PowerPC architecture to 64-bit x86-64 Linux systems.

Sophos researchers noted that the use of generic SysV persistence in these new samples removes the previous dependency on WatchGuard-specific firmware. This shift allows the implant to operate across a much broader array of enterprise network appliances, significantly increasing the potential scale of Russian intelligence collection.

Expanded Intelligence Capabilities

Beyond its new architecture, the upgraded botnet possesses expanded capabilities designed for deep network surveillance. The implant can now perform active network scanning and selective packet capture, allowing attackers to monitor traffic in real time. Additionally, the malware is capable of collecting CPU information and password hashes from the compromised systems.

By compromising the Firewall Management Center, Sandworm effectively gains a "god-eye" view of the target network. This positioning allows the GRU-linked unit to observe sensitive traffic and move laterally through the environment with high privileges, turning a security appliance into a tool for infiltration.

The Sandworm Threat

Sandworm is a notorious unit within the GRU, known for high-impact destructive attacks, including the NotPetya outbreak and the disruption of Ukraine's power grid. The current focus on network-management infrastructure suggests a strategic pivot toward long-term persistence and intelligence gathering within critical enterprise environments.

Security teams are advised to prioritize patching the identified Cisco FMC vulnerabilities to prevent root-level compromise. While the architectural shift to x86-64 Linux makes the malware more versatile, the reliance on specific CVE chains provides a clear window for defense and remediation.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.