CASE FILE
INC-2022-0223-CBLINK
JUN 2019 – MAR 2022
TLP:CLEAR
// Cyber Incident Case File — Nation-State Espionage / Worm-Enabled Botnet

CYCLOPS BLINK

COMPILED: 2026-09-02  |  INCIDENT DATE RANGE: ~JUNE 2019 – MARCH 2022 (DISCLOSED FEB 23, 2022)  |  SOURCES: CISA, NCSC-UK, DOJ, MITRE ATT&CK, Kudelski Security, Trend Micro, Talos, Bleeping Computer
Incident Type: NATION-STATE ESPIONAGE (Infrastructure Pre-Positioning)
Secondary Type: WORM / SELF-PROPAGATING
Attribution: HIGH
Severity: CRITICAL
Era: Post-ATT&CK (Enterprise Framework)
ATT&CK Framework: Enterprise
~2.5 YRS
Undetected Before Public Disclosure
THOUSANDS
Devices In Botnet (WatchGuard + ASUS, Per DOJ)
2ND
DOJ Disruption of a Sandworm Botnet (After VPNFilter, 2018)
0 CONFIRMED
Documented Offensive Uses of the Botnet Before Takedown
00
Case File Overview
Incident NameCYCLOPS BLINK
Date Range~Jun 2019 – Mar 2022 (active); Feb 23 2022 (disclosed)
Incident TypeNation-State Espionage / Infrastructure Pre-Positioning
Primary ActorSandworm Team (GRU Unit 74455)
Attribution Confidence[HIGH]
Primary TargetWatchGuard Firebox/XTM firewalls; ASUS SOHO routers (global)
Victim CountThousands of devices, per DOJ (exact figure not independently published)
Initial DiscoveryFeb 23, 2022 (public disclosure)
Discovered ByCISA / FBI / NSA / NCSC-UK joint advisory (AA22-054A)
Dwell Time~2.5 years (Jun 2019 – Feb 2022)
Primary ImpactDurable botnet infrastructure; no confirmed destructive/espionage payload delivered before disruption
ATT&CK FrameworkEnterprise
MITRE Campaign IDNone identified — tracked as Software S0687 under Group G0034
Historical IOCsNot flagged historical — incident is within the standard 5-year detection-utility window as of 2026, though infrastructure has long since rotated post-disruption
01
Situation Overview

CYCLOPS BLINK is a modular botnet malware built and operated by Sandworm Team, the Russian GRU's Unit 74455, that quietly compromised thousands of WatchGuard Firebox/XTM firewalls and ASUS home/small-office routers around the world starting around June 2019 — roughly fourteen months after Sandworm's previous botnet, VPNFilter, was publicly exposed and disrupted by the FBI in May 2018 (CISA AA22-054A, Feb 23 2022). It sat undiscovered for approximately two and a half years before a joint CISA/FBI/NSA/NCSC-UK advisory revealed its existence on February 23, 2022 — one day before Russia's full-scale invasion of Ukraine — and a U.S. Department of Justice court-authorized operation remotely disabled the botnet's remaining command-and-control nodes the following month.

Why it matters: CYCLOPS BLINK is the clearest documented example of a nation-state building durable, long-term botnet infrastructure specifically on network-edge devices — firewalls and consumer/SOHO routers — precisely because those devices sit outside the reach of the endpoint monitoring, EDR telemetry, and internal-network logging that would normally catch a multi-year intrusion. Unlike a traditional espionage operation aimed at stealing a specific target's data, CYCLOPS BLINK's design and behavior (see Section 03) reflect infrastructure-building for future, unspecified use — a proxy and staging layer Sandworm could draw on when needed, not a campaign against any single victim.

Its proximity to the Ukraine invasion generated significant contemporaneous speculation that the botnet was being prepared for use in or alongside the war — CISA's advisory itself was published with explicit "shields up" framing amid heightened concern about Russian cyber activity tied to the invasion. It is important to be precise about what is and is not established here: public sources reviewed for this card document that the botnet existed, was operated by Sandworm, and was disabled before any confirmed offensive use — they do not establish a proven, specific intent to use it against Ukraine or NATO targets. That distinction between documented fact and contemporaneous framing is preserved throughout this card (see Section 07 and Section 09).

This is also the second time the exact same disruption playbook — a DOJ-authorized, FBI-executed remote remediation operation — was run against Sandworm-operated botnet infrastructure specifically, after VPNFilter in 2018. That repetition is itself analytically significant: it establishes court-authorized remote botnet remediation as a standing, repeatable U.S. government tool against this class of nation-state infrastructure, not a one-off legal improvisation (see Section 07C and Section 09).

02
Background & Context

Direct historical precedent — VPNFilter (2018). In May 2018, Cisco Talos and the FBI exposed and disrupted VPNFilter, a Sandworm-operated botnet that had compromised over 500,000 SOHO routers and network-attached storage devices across 54 countries (Cisco Talos, May 2018; DOJ, May 2018). The FBI seized a domain used in VPNFilter's command-and-control chain under a court-authorized warrant. CISA's later advisory on Cyclops Blink states plainly that the new malware appeared "fourteen months after VPNFilter was disrupted" and functions as its replacement framework — the same actor, the same target category (network-edge devices), and, as this incident shows, ultimately the same disruption mechanism.

Technology landscape. By 2019, WatchGuard Firebox/XTM appliances and ASUS routers were widely deployed in small-business and home environments precisely because they are largely "install and forget" devices — appliances that receive periodic firmware updates but are not treated by their owners, or by the broader security industry, as endpoints requiring active monitoring the way a laptop or server would be. This operational reality is what makes the device class attractive to an actor building long-term infrastructure: low monitoring, wide deployment, and firmware-level access once compromised.

Geopolitical climate. The campaign's active window (2019–2022) spans a period of steadily escalating tension between Russia and the West, culminating in the February 24, 2022 invasion of Ukraine. Sandworm has a well-documented history of destructive and disruptive operations tied to Russia's conflict with Ukraine specifically (see actor card, Section 02) — the 2015 and 2016 Ukrainian power grid attacks, NotPetya in 2017. CYCLOPS BLINK's discovery one day before the invasion, in an advisory explicitly framed around "shields up" concern, sits inside that pattern even though — as stated in Section 01 — no source reviewed confirms the botnet was built or earmarked specifically for use against Ukraine.

Pre-incident indicators. No public source reviewed for this card documents any pre-2022 detection, alert, or customer report that identified Cyclops Blink activity before the joint advisory — this was, by all available evidence, a genuinely blind multi-year run for defenders (see Section 05).

03
Kill Chain Narrative Phase-by-phase account of the attack as it progressed
Initial Device Compromise BLIND
Sandworm's initial-access mechanism differed by device platform, and the two vectors are worth stating precisely rather than collapsing into one. On WatchGuard Firebox/XTM appliances, Sandworm exploited CVE-2022-23176, a privilege-escalation flaw in Fireware OS's management interface that let an attacker holding any unprivileged, authenticated credential escalate to full administrative control (see vuln card: WatchGuard Firebox Auth Bypass). On ASUS routers, the documented vector is different and less exotic: ASUS's own guidance points to default administrator credentials and internet-exposed remote management as the practical access path, not a specific disclosed CVE (Bleeping Computer, Mar 2022; ASUS advisory). Neither vector required more than routine internet exposure and, on the WatchGuard side, a low-privilege foothold — no zero-click or highly sophisticated exploitation chain was documented on either platform.
A foothold on the device's management plane — however it was obtained — gave Sandworm the access level needed to tamper with the device's own firmware-update mechanism.
Firmware-Level Persistence BLIND
Cyclops Blink deploys itself in the form of a malicious firmware "update," abusing the affected devices' standard upgrade process to install persistently (CISA AA22-054A). On WatchGuard devices specifically, this was possible because Firebox firmware validated update integrity using an HMAC computed with a hard-coded key shared across the product line — once Sandworm held a privileged session, it could recompute a valid HMAC for its own modified firmware image, and the device accepted it as a legitimate vendor update (Kudelski Security Research, Apr 2022). The malware has read/write access to the device filesystem and can replace legitimate binaries (e.g. the device's own install_upgrade component) with modified versions, meaning it survives reboots and ordinary restarts — the two things that would normally clear a less sophisticated implant (NCSC Malware Analysis Report, Feb 23 2022).
Reboot-surviving, firmware-level persistence meant Sandworm could treat compromised devices as durable, long-term infrastructure rather than a foothold that needed to be re-established after every restart or routine maintenance cycle.
Tiered, Encrypted C2 Infrastructure Assembly BLIND
Cyclops Blink organizes infected devices into clusters, each configured with its own list of command-and-control IP addresses and ports (NCSC Malware Analysis Report). Communications between infected devices and C2 servers run over TLS with individually generated keys and certificates per deployment, layered with AES-256-CBC encryption and multiple redundant C2 channels — deliberate engineering to make the traffic both hard to detect at the network level and resilient to any single channel being taken down. Sandworm operators managed the C2 layer by connecting to it through the Tor network, adding a further layer of operator-side anonymity on top of the malware's own traffic obfuscation.
A resilient, redundant, Tor-fronted C2 architecture meant the botnet as a whole could not be meaningfully disrupted by taking down any single node or IP — a structural design choice that anticipated, and was built to survive, the kind of takedown attempt that eventually succeeded only because it operated at the scale of a coordinated, court-authorized, device-by-device remote remediation rather than a single infrastructure seizure.
Dormant Pre-Positioning BLIND
Cyclops Blink's core functionality, as documented by CISA and NCSC, is comparatively modest by itself: send infected-device information back to a controller, and download and execute additional modules or files on command. The modular "add capability later" design is the operative feature — it lets Sandworm decide what any given device or cluster is used for at a later point, rather than committing to a fixed purpose at time of infection. No source reviewed for this card documents Cyclops Blink being used, at any point before the March 2022 disruption, to conduct DDoS attacks, exfiltrate specific victim data, or stage a destructive payload — the botnet's observed behavior throughout its known active life is consistent with infrastructure-building and readiness, not active operational use.
A large, dormant, globally distributed pool of compromised devices — capable of being tasked with new modules on short notice — represented a standing capability Sandworm could activate for offensive purposes at a time and for a use of its choosing, which is precisely the risk that triggered the eventual preemptive disruption rather than a wait-and-monitor response.
Discovery, Disclosure & Court-Authorized Disruption DETECTED — Feb 23, 2022, by CISA/FBI/NSA/NCSC-UK
On February 23, 2022, CISA, the FBI, NSA, and the UK's NCSC jointly published advisory AA22-054A, publicly naming Cyclops Blink, attributing it to Sandworm, and tying its WatchGuard-side initial access to CVE-2022-23176. WatchGuard worked with the four agencies to provide detection and non-standard remediation tooling for affected customers. On March 18, 2022, a U.S. court authorized the FBI to remotely and covertly copy and remove Cyclops Blink from remaining command-and-control devices on both WatchGuard and ASUS platforms, without the consent (and in most cases without the knowledge, until after the fact) of the devices' owners — the Justice Department announced the operation as complete and successful in early April 2022 (DOJ press release, Apr 6 2022).
04
TTPs — MITRE ATT&CK Mapping Enterprise Framework · Software S0687
Initial Access
T1190
Exploit Public-Facing Application
[HIGH] WatchGuard Firebox/XTM devices compromised via CVE-2022-23176, an exposed management-interface privilege-escalation flaw.
Initial Access
T1078
Valid Accounts
[MEDIUM] ASUS router compromise documented as credential/exposure-based (default or weak admin credentials, internet-exposed remote management) rather than a disclosed CVE.
Persistence / Defense Evasion
T1601.001
Modify System Image: Patch System Image
[HIGH] Malware installs as a malicious firmware "update," abusing a hard-coded HMAC signing key to pass integrity validation on WatchGuard devices.
Resource Development
T1584.008
Compromise Infrastructure: Network Devices
[HIGH] Thousands of SOHO/edge devices compromised and organized into clusters as durable, reusable infrastructure rather than a single-use foothold.
Command & Control
T1071.001
Application Layer Protocol: Web Protocols
[HIGH] C2 communications carried over TLS to blend with legitimate management-plane traffic.
Command & Control
T1573.001
Encrypted Channel: Symmetric Cryptography
[HIGH] AES-256-CBC layered on top of TLS for C2 traffic, per NCSC malware analysis.
Command & Control
T1090.003
Proxy: Multi-hop Proxy
[HIGH] Sandworm operators connected to the C2 layer via the Tor network for operator-side anonymity.
Command & Control
T1105
Ingress Tool Transfer
[HIGH] Modular architecture allows new capability modules to be downloaded and executed on infected devices on command.
Discovery
T1082
System Information Discovery
[HIGH] Core malware functionality sends infected-device information back to the controlling C2 server.
05
Defender Post-Mortem What was missed, when, and why
PHASES 1–4
(~2.5 YEARS)
MISSED ENTIRELY
No telemetry existed for defenders to miss. Network-edge appliances like Firebox/XTM firewalls and consumer ASUS routers are not, by design or by prevailing industry practice, instrumented with EDR-style monitoring the way a server or laptop endpoint would be. There was no log source, alert, or detection surface available to any individual device owner that could have surfaced firmware-level compromise during the ~2.5 years the botnet operated undetected. This is a genuinely different failure mode than "logs existed but went unreviewed" — the visibility gap was structural and industry-wide, not a specific organization's oversight.
DEC 2021
ACCIDENTAL PARTIAL REMEDIATION
WatchGuard's routine December 2021 Fireware patch closed the CVE-2022-23176 authorization gap before the company or the public knew it was closing a live, multi-year nation-state intrusion vector. This is neither a "missed" detection nor a "detected" one in the normal sense — it is a case of a maintenance patch accidentally interrupting an active campaign months before anyone understood what had actually been happening, illustrating that routine patch hygiene has real, if unrecognized, security value even absent specific threat intelligence.
POST-INCIDENT
LESSON ADOPTED
Following disclosure, WatchGuard published dedicated detection and non-standard remediation tooling specifically because a routine firmware upgrade alone was documented as insufficient to remove an already-active infection (the malware's persistence mechanism lives inside the update-validation path itself). More broadly, this incident — alongside VPNFilter before it — contributed to a growing industry and CISA-level emphasis on treating network-edge/perimeter devices as a monitored asset class in their own right, including firmware-integrity verification and default-disabling of internet-facing management interfaces, rather than as "set and forget" infrastructure.
06
Technical Artifacts Malware, tools, CVEs, IOCs
CYCLOPS BLINK (MITRE ATT&CK Software S0687)
botnet modular firmware-persistent
Modular botnet malware written to run on network-device firmware (WatchGuard Firebox/XTM, ASUS routers). Core module reports device information to C2 and can fetch/execute additional modules on command. Persists as a malicious firmware image; communications encrypted with TLS + AES-256-CBC over a tiered C2 architecture managed through Tor. Successor to VPNFilter (2018).
CVE-2022-23176 — WatchGuard Firebox/XTM Privilege Escalation
initial access CVSS 8.8
Primary documented initial-access vulnerability on the WatchGuard side of this campaign — full root-cause analysis, CVSS breakdown, patch guidance, and purple-team content maintained in its own vuln card (see vuln card: WatchGuard Firebox Auth Bypass) rather than duplicated here.
Hard-coded HMAC Firmware-Signing Key (WatchGuard, undocumented separate CVE)
persistence mechanism not CVE-numbered
A static, hard-coded key used across the Firebox product line to compute the HMAC validating firmware update images. Once an attacker held a privileged session (via CVE-2022-23176), this weakness let them push a self-signed, malicious firmware image that the device accepted as legitimate. No source reviewed assigns this weakness its own CVE identifier — documented here as an artifact of the exploitation chain, not as a separately tracked vulnerability.
⚠ All IPs and domains defanged. Reconstruct before use in detection tooling. Infrastructure listed here was active during the 2019–2022 campaign window and has long since been rotated/dismantled following the March 2022 disruption — treat as historical/research reference, not a live blocklist.
TypeValue / DescriptionSourceDate
CVECVE-2022-23176 (WatchGuard Firebox/XTM privilege escalation)CISA / NVD2022-02-23
MALWARE IDMITRE ATT&CK Software S0687 (Cyclops Blink)MITRE ATT&CK2022
BEHAVIORALTLS-wrapped C2 traffic on device management plane, tiered/clustered C2 IP lists, AES-256-CBC-encrypted payload, Tor-relayed operator accessNCSC Malware Analysis Report2022-02-23
BEHAVIORALUnauthorized firmware "update" event on WatchGuard Firebox/XTM device outside a logged, administrator-initiated upgrade actionWatchGuard / CISA remediation guidance2022
NOTENo specific C2 IP addresses, domains, or file hashes for Cyclops Blink samples were located in the public-source subset reviewed for this card (CISA/NCSC published detailed detection signatures and YARA/Snort rules in companion technical documents not fully mirrored in the sources retrieved here). This is stated as a research-pass gap, not a claim that no such IOCs exist publicly — an analyst needing operational IOCs should pull directly from the NCSC Malware Analysis Report PDF and CISA's companion indicator files.
07
Consequences Strategic · Technical · Legal/Regulatory
⬡ Strategic / Geopolitical
The disruption operation removed a standing, globally distributed capability from Sandworm's hands one day before Russia's invasion of Ukraine reached full scale — contemporaneous coverage widely framed this as a preemptive denial of potential wartime infrastructure, and CISA's own advisory carried explicit "shields up" framing tied to the invasion. That framing is a reasonable strategic reading of the timing, but it should be held separately from proven fact: no source reviewed for this card documents a confirmed, specific plan to use Cyclops Blink against Ukrainian or NATO targets — what is documented is that a large, flexible, dormant capability existed and was neutralized before any confirmed offensive use, at a moment when Russian cyber activity was under maximum global scrutiny.
⬡ Technical / Capability
WatchGuard published dedicated, non-standard detection and remediation tooling for affected customers, since a routine firmware upgrade alone did not reliably remove an active infection. More broadly, the incident reinforced an industry-wide lesson (shared with VPNFilter before it) that network-edge and SOHO devices function as a durable, largely unmonitored attack surface — pushing renewed vendor and CISA emphasis on disabling internet-facing management interfaces by default and on firmware-integrity verification as a standard practice rather than an edge case.
⬡ Legal / Regulatory
The March 2022 operation followed the same legal mechanism the FBI used against VPNFilter in 2018 — a court-authorized warrant permitting the government to remotely access and remediate malware on privately owned devices without the owners' consent or, in most cases, prior knowledge. Running that mechanism a second time against the same actor's infrastructure moves it from a one-off legal improvisation toward an established, repeatable government tool. This is not without genuine debate: remote government access to private devices, even for unambiguously remedial purposes and under judicial authorization, raises real questions about scope, oversight, and precedent that extend beyond this specific case — sources reviewed for this card document the operation's legal basis and its stated success, but do not resolve that broader debate, and this card does not take a position on it.
08
Attribution
ATTRIBUTION CONFIDENCE: HIGH
Attributed ToSandworm Team
SponsorRussian GRU, Unit 74455
Formal AttributionJoint CISA/FBI/NSA/NCSC-UK advisory (AA22-054A, Feb 23 2022)
IndictmentsNone specific to this campaign; six GRU Unit 74455 officers previously indicted (2020) for related Sandworm activity including NotPetya and the 2018 Olympics attack
Companion Actor Card2026-09-02_SANDWORM.html
Primary EvidenceMulti-agency joint technical attribution (US + UK), consistent with established Sandworm/VPNFilter TTP lineage
Competing HypothesesNone substantive identified — attribution is not contested in sources reviewed
What Would Change AssessmentA credible, independently corroborated alternative attribution has not been proposed in any source reviewed; this would require new, contradicting technical evidence, which has not surfaced

Attribution here rests on formal, joint technical assessment by four government cybersecurity agencies across two allied nations (CISA, FBI, and NSA in the U.S.; NCSC in the UK), publishing consistent findings under a shared advisory. This is a stronger evidentiary basis than a single-vendor private assessment, and it is consistent with — not standing apart from — the broader body of independent vendor tracking (CrowdStrike's VOODOO BEAR, ESET's TeleBots, Dragos's ELECTRUM, Microsoft's Seashell Blizzard/IRIDIUM, all converging on the same underlying actor cluster; see actor card Section 01 for the full alias/tracking-designation picture). No source reviewed for this card raises a serious competing attribution hypothesis. Full identity, sponsorship, and confidence-rationale detail for the actor itself lives in the companion Sandworm Team actor card rather than being duplicated here, per this card's relationship to actor cards.

09
Historical Significance

CYCLOPS BLINK is the second confirmed case of the U.S. Department of Justice using a court-authorized, remote, non-consensual remediation operation to disable a Sandworm-operated botnet — the first being VPNFilter in 2018. Two data points is a thin base for declaring a "doctrine," but it is enough to establish that this specific legal and operational mechanism is now a standing, repeatable tool in the U.S. government's toolkit against nation-state edge-device botnet infrastructure, rather than a one-time legal improvisation. Any future incident card documenting a similar takedown should treat this pairing (VPNFilter → Cyclops Blink) as the baseline precedent, not a novel development.

It is also one of the clearest documented cases of a nation-state building large-scale botnet infrastructure as a standing capability rather than as a tool aimed at a specific target or objective — the "dormant pre-positioning" model described in Section 03. That distinction matters for how defenders and policymakers should think about network-edge device compromise generally: the absence of any confirmed offensive use of the botnet before it was disrupted does not mean the compromise was low-stakes while it lasted. It means the capability existed, fully formed and ready, for roughly two and a half years before anyone outside Sandworm knew about it — a genuinely different risk profile than an intrusion aimed at immediate data theft, and one that argues for treating "silent, purposeless-seeming" edge-device compromise as seriously as an active, damaging one.

Finally, the incident is a clean case study in how vulnerability disclosure interacts with active law-enforcement operations (see the companion vuln card's Section 04 and Section 07 for the fuller analysis) — WatchGuard patched the underlying CVE quietly in December 2021 and held back public framing of its severity for roughly two months at DOJ's direction, ahead of the March 2022 takedown. That is a genuinely different disclosure model than the standard researcher-vendor coordinated disclosure this field is usually taught around, and it remains a live, unresolved tension worth studying on its own terms rather than folding into ordinary CVD norms.

10
References URLs are NOT defanged — navigate directly