ATT&CKSoftwareCyclops Blink

Cyclops Blink

S0687

Malware.View on attack.mitre.org

About this malware

Cyclops Blink is a modular malware that has been used in widespread campaigns by Sandworm Team since at least 2019 to target Small/Home Office (SOHO) network devices, including WatchGuard and Asus. Cyclops Blink is assessed to be a replacement for VPNFilter, a similar platform targeting network devices.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1005
Data from Local System

Cyclops Blink can upload files from a compromised host.

T1016
System Network Configuration Discovery

Cyclops Blink can use the Linux API `if_nameindex` to gather network interface names.

T1036.005
Match Legitimate Resource Name or Location

Cyclops Blink can rename its running process to [kworker:0/1] to masquerade as a Linux kernel thread. Cyclops Blink has also named RC scripts used for persistence after WatchGuard artifacts.

T1037.004
RC Scripts

Cyclops Blink has the ability to execute on device startup, using a modified RC script named S51armled.

T1041
Exfiltration Over C2 Channel

Cyclops Blink has the ability to upload exfiltrated files to a C2 server.

T1057
Process Discovery

Cyclops Blink can enumerate the process it is currently running under.

T1070.006
Timestomp

Cyclops Blink has the ability to use the Linux API function `utime` to change the timestamps of modified firmware update images.

T1071.001
Web Protocols

Cyclops Blink can download files via HTTP and HTTPS.

T1082
System Information Discovery

Cyclops Blink has the ability to query device information.

T1083
File and Directory Discovery

Cyclops Blink can use the Linux API `statvfs` to enumerate the current working directory.

T1090.003
Multi-hop Proxy

Cyclops Blink has used Tor nodes for C2 traffic.

T1105
Ingress Tool Transfer

Cyclops Blink has the ability to download files to target systems.

T1106
Native API

Cyclops Blink can use various Linux API functions including those for execution and discovery.

T1132.002
Non-Standard Encoding

Cyclops Blink can use a custom binary scheme to encode messages with specific commands and parameters to be executed.

T1140
Deobfuscate/Decode Files or Information

Cyclops Blink can decrypt and parse instructions sent from C2.

View all 21 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. NCSC CISA Cyclops Blink Advisory February 2022 Open source
    NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022.
  2. NCSC Cyclops Blink February 2022 Open source
    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.
  3. Trend Micro Cyclops Blink March 2022 Open source
    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.