SOPHOS Counter Threat Unit researchers have identified a new 64-bit Linux variant of the Cyclops Blink malware on multiple compromised Cisco Firewall Management Centre (FMC) devices. The discovery marks a change from earlier campaigns, which mainly targeted 32-bit PowerPC small-office routers. The new implant runs on x86-64 Linux and uses generic System V (SysV) persistence, potentially widening the range of compatible network appliances.
The initial access route has not been confirmed; the report says exploitation of unpatched vulnerabilities or the use of exposed administrative credentials are possible explanations.
The malware uses a parent controller and five worker modules. It disguises the controller as the legitimate-looking `kworker/0:1` process, installs a startup script and executable in system directories, and restores itself after reboot. Its capabilities include collecting host and network information, discovering adjacent networks and services, transferring files, executing additional payloads in memory and capturing packets that match operator-supplied patterns.
The implant also changes outbound firewall rules to permit communications with operator-controlled infrastructure and uses encrypted TCP connections for command and control. Sophos assesses with moderate confidence that the Russia-based IRON VIKING group, associated with Sandworm, is behind the campaign; this is an assessment rather than confirmed attribution.
Defenders are advised to inspect Linux-based network appliances for processes imitating kernel threads, unexpected startup scripts and unauthorised outbound firewall rules or connections. The report also recommends applying vendor patches, rotating administrative credentials, restricting management interfaces to trusted internal networks and monitoring them for unusual access.