Threat Intelligence

Russian 'Sandworm' Hackers Return with Upgraded Botnet Malware Targeting Cisco Devices

Dark Reading · 15 Sept 2026
Key Takeaway Keep network edge devices like routers and firewalls patched and monitored, as they remain a top target for sophisticated attackers.

The Russian threat group known as Sandworm has been observed exploiting vulnerabilities in Cisco networking devices to deploy an updated version of its Cyclops Blink botnet malware. This is the same malware family the FBI took action to disrupt back in 2022, indicating the group has rebuilt and refined its tooling despite that earlier setback.

Sandworm is a well known and highly capable state sponsored group, and its return with new botnet capability is a reminder that disrupted malware operations can resurface in improved form. Devices that sit at the network edge, such as routers and firewalls, remain attractive targets because they often run outdated firmware and are less closely monitored than desktop endpoints.

Key Takeaway: Australian small businesses should ensure Cisco and other network edge devices are kept fully patched and regularly checked for firmware updates, since these devices are a preferred entry point for sophisticated state backed attackers.

Sandworm Cisco vulnerabilities botnet malware

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.