Cybersecurity Research

Cyclops Blink Malware Returns, Now Targeting Linux Firewalls Directly

Sophos · 11 Sept 2026
Key Takeaway Regularly patch and monitor network edge devices like firewalls, and treat any unusual process activity on these systems as a potential sign of compromise.

Security researchers at Sophos have identified a new version of the Cyclops Blink malware, a sophisticated tool linked to the Russia-based hacking group known as Sandworm or Seashell Blizzard. The malware was discovered disguised as a file called 'timezone_check' on multiple compromised Cisco Firewall Management Center (FMC) devices, and is believed to be connected to a campaign Cisco disclosed publicly in September.

Unlike the 2022 version, which specifically targeted WatchGuard firewall firmware, this new variant runs on standard 64-bit Linux systems and uses a more generic method to maintain persistence on infected devices. This change means the malware could potentially be adapted to compromise a wider range of network security appliances, not just those from a single vendor. Once installed, it can perform network reconnaissance, monitor network traffic, transfer files, and execute additional malicious payloads, effectively turning a compromised firewall into a foothold for deeper attacks on a business's internal network.

The malware is built to avoid detection, disguising its main process as a legitimate Linux kernel task to blend in with normal system activity. This modular design allows different malicious functions to run independently, making the threat both flexible and resilient against basic troubleshooting or removal attempts.

Cyclops Blink Cisco Firewall Malware Sandworm Network Security
Primary source ncsc.gov.uk -> cisa.gov ->

Summarised by CISO AI from Sophos. We link back to every original so you can read it yourself.