Cyclops Blink Malware Targeting WatchGuard Firewalls
ID: f8f2fc95-4030-57dd-b07f-05255f7795ee
STIX ID: report--f8f2fc95-4030-57dd-b07f-05255f7795ee
Feed Name: Kudelski Security
Threat Score
The advisory describes Cyclops Blink, a modular firmware-based implant linked to the Sandworm/Voodoo Bear APT that targets WatchGuard Firebox SOHO devices by abusing the firmware upgrade/HMAC process to achieve persistent, botnet-style control; it provides technical details, observed capabilities (C2, file collection, command execution, packet sniffing), scope (~1,500+ impacted IPs, ~40% in the US), detection guidance, IOCs, and remediation/upgrade recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
