Back to Feed
Nation-stateSep 14, 2026

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

Sandworm group exploits Cisco vulnerabilities to deploy upgraded Cyclops Blink botnet.

Summary

The Russian-linked Sandworm threat group has been observed exploiting a chain of Cisco vulnerabilities to deploy an upgraded version of the Cyclops Blink botnet. This botnet was previously disrupted by the FBI in 2022, indicating a resurgence and evolution of the malware. The exploitation of Cisco devices allows Sandworm to gain a foothold and spread the sophisticated malware.

Indicators of Compromise

  • malware — Cyclops Blink

Entities

Sandworm (threat_actor)Cyclops Blink (product)Cisco (vendor)