Cyclops Blink Malware Targets Cisco Firewall Devices
Article Content
- •Cyclops Blink malware targets Cisco FMC devices, providing persistent remote access.
- •The malware is linked to the Russian IRON VIKING threat group, enhancing its capabilities.
- •Cisco issued an advisory on September 9, 2026, detailing the malware's features and risks.
In August 2026, researchers from the Counter Threat Unit™ (CTU) discovered a malicious 64-bit Linux executable named timezone_check on compromised Cisco Firewall Management Center (FMC) devices. This malware variant, linked to the Russian IRON VIKING threat group, offers persistent remote access and advanced capabilities such as network discovery and packet surveillance. Cisco issued a public advisory on September 9, 2026, detailing the campaign. The Cyclops Blink malware is a modular framework that operates through a parent controller and multiple worker modules, enhancing its stealth and functionality. Unlike previous versions, this variant utilizes generic System V persistence, making it compatible with a broader range of devices. The malware's architecture allows for concurrent task execution and effective command and control operations. Organizations are advised to implement mitigation measures as the threat landscape evolves.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track IRON Viking, Cyclops Blink and WatchGuard in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…