Nation-stateSep 14, 2026
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
Sandworm group exploits Cisco vulnerabilities to deploy upgraded Cyclops Blink botnet.
Summary
The Russian-linked Sandworm threat group has been observed exploiting a chain of Cisco vulnerabilities to deploy an upgraded version of the Cyclops Blink botnet. This botnet was previously disrupted by the FBI in 2022, indicating a resurgence and evolution of the malware. The exploitation of Cisco devices allows Sandworm to gain a foothold and spread the sophisticated malware.
Indicators of Compromise
- malware — Cyclops Blink
Entities
Sandworm (threat_actor)Cyclops Blink (product)Cisco (vendor)