A newly recognized Cyclops Blink variant has resurfaced on compromised Cisco Safe Firewall Administration Heart (FMC) home equipment, including lively internal-network scanning and programmable packet-sniffing capabilities to an already mature modular implant.
Assessed with excessive confidence that the exercise has a Russian nexus, with a moderate-confidence hyperlink to IRON VIKING additionally tracked as Sandworm and Seashell Blizzard.
Cisco Talos publicly disclosed the broader FMC exploitation exercise on September 9, warning that attackers abused two vulnerabilities CVE-2026-20079 and CVE-2026-20316 to realize entry, deploy reverse shells and proxy tooling, steal machine knowledge, and finally set up Cyclops Blink.
CVE-2026-20079 is an authentication-bypass flaw that may permit unauthenticated distant attackers to execute scripts and procure root entry on affected FMC gadgets, whereas CVE-2026-20316 permits login with a low-privileged account.
The event marks a big evolution for Cyclops Blink, a malware household publicly attributed by U.S. and UK authorities to the GRU-linked Sandworm operation in 2022.
Earlier samples primarily focused WatchGuard Firebox gadgets working 32-bit PowerPC Linux.
The newly noticed construct is a 64-bit x86-64 ELF implant with generic System V init persistence, probably making it transportable throughout a wider set of Linux-based network-management, VPN, routing and safety home equipment.
The timezone_check implant operates by way of a mum or dad controller and 5 forked employee modules.
The controller disguises itself as [kworker/0:1], a reputation supposed to resemble respectable Linux kernel-worker exercise in course of listings.
It coordinates its modules over devoted inter-process communication channels, synchronizes configuration, encrypts collected output and relays it over TLS-protected outbound command-and-control connections.
The controller additionally modifies native firewall coverage to protect its C2 entry. It provides iptables OUTPUT-chain ACCEPT guidelines for TCP ports 43856 and 49172, the ports utilized by the implant’s C2 communications.
Researchers at Sophos Counter Risk Unit (CTU) analyzed, the 64-bit Linux executable, named timezone_check, in August 2026.
Cyclops Blink variant
The malware accommodates a hard-coded C2 handle, 89[.]34[.]96[.]56, and makes an attempt TLS classes with out standard certificates validation, then exchanges knowledge by way of a customized protocol fairly than HTTP.

Its C2 configuration could be remotely adjusted: operators can change C2 addresses, drive a direct beacon, change connection timing, restart the implant or load alternative employee modules.
This modular design offers resilience and permits a number of surveillance or post-compromise duties to run concurrently.
Probably the most consequential additions are modules for community discovery and selective site visitors assortment.
Module 0x11 enumerates regionally related IPv4 networks and scans both attacker-specified ranges or an embedded record of ports linked to administration, file-sharing, net, listing, VPN, VMware and network-management companies.
The scanner sends crafted Ethernet, IPv4 and TCP frames over uncooked packet sockets, identifies open ports by way of SYN-ACK replies, performs light-weight TCP handshakes and might retrieve HTTP responses or conduct TLS probing.
Its built-in targets embody SSH, Telnet, SMB, LDAP, DNS, SNMP, VMware companies, HTTP/HTTPS and VPN-related ports.
From an FMC’s privileged place, this functionality might expose inside administration methods and companies not reachable from the general public web.
Module 0x12 provides focused packet seize. It opens an AF_PACKET uncooked socket to gather seen Ethernet frames, parses IPv4 TCP and UDP payloads, and searches them utilizing an Aho-Corasick-style multi-pattern matching routine.
As an alternative of exfiltrating all site visitors, operators can configure length, protocol and handle filters, ports, and content material phrases.
Matching packets are retained in timestamped pcap-style data, probably exposing cleartext credentials, authentication cookies, entry tokens, administrative instructions and delicate utility knowledge.
The malware maintains persistence by copying itself to /lib/tz/timezone_check, creating /and many others/init.d/timezone_check, and putting in SysV startup hyperlinks for runlevels 2 by way of 5.
The time zone-themed paths and repair identify are supposed to seem benign. Profitable set up additionally strongly suggests execution with root-level permissions as a result of the implant should write beneath /lib and /and many others.
A separate module helps file uploads, HTTP/HTTPS downloads, arbitrary payload execution and in-memory code loading.
It may register downloaded ELF binaries as further modules, permitting operators to increase the implant with out changing all the framework.
The module additionally makes use of Google Public DNS at 8.8.8.8 over DNS-over-HTTPS entry to resolve transfer-host names, bypassing native resolver infrastructure and decreasing standard DNS-log proof.
The marketing campaign demonstrates why FMC and comparable network-edge administration methods should be handled as high-value intrusion factors.
Cisco noticed UAT-11823 chaining the 2 FMC flaws earlier than putting in a Netcat reverse shell, proxy instruments and the Cyclops Blink variant.
Organizations ought to instantly apply Cisco’s out there hotfixes, examine FMC gadgets for anomalous SysV companies and the timezone_check paths, evaluation outbound TLS classes on ports 43856 and 49172, and hunt for raw-socket scanning, uncommon inside probes and suspicious packet-capture habits.
The renewed framework just isn’t merely a persistence implant.
On a compromised management-plane equipment, Cyclops Blink can grow to be an inside reconnaissance platform, a selective network-surveillance sensor and a staging level for broader Sandworm-linked operations.
IOCs
| Indicator | Kind | Context |
| 89[.]34[.]96[.]56 | IP handle | Cyclops Blink C2 server |
| /lib/tz/timezone_check | File path | Utilized by 2026 model of Cyclops Blink |
Word: IP addresses and domains are deliberately defanged (e.g., [.]) to stop unintentional decision or hyperlinking. Re-fang solely inside managed menace intelligence platforms corresponding to MISP, VirusTotal, or your SIEM.
★ Be taught 7 Metric-Gated AI SOC Deployment Phases – Obtain Free AI SOC Deployment Playbook 2026.








